Splunk Search

How to display warning based on SPL?

jonaclough
Path Finder

Is there a way of showing a warning to the user based on their SPL.

My use case is that users should not generally search indexes which are fed into an accelerated data model. Specifically it's faster and more accurate to search the network_traffic ADM than a firewall index.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jonaclough,

sorry: it isn't possible to define an automatic warning because it depends only on your specific data and it's also infruenced by other factors.

The only possible approach (for my knowledge) is the definition of a list of tips to use your data to share to all your users.

A kind of quick reference guide to use your own data.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @jonaclough,

sorry: it isn't possible to define an automatic warning because it depends only on your specific data and it's also infruenced by other factors.

The only possible approach (for my knowledge) is the definition of a list of tips to use your data to share to all your users.

A kind of quick reference guide to use your own data.

Ciao.

Giuseppe

jonaclough
Path Finder

If admission rules had an extra rule action option "issue warning" rather than just "filter search" that would do the job. 

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...