Splunk Search

How to display warning based on SPL?

jonaclough
Path Finder

Is there a way of showing a warning to the user based on their SPL.

My use case is that users should not generally search indexes which are fed into an accelerated data model. Specifically it's faster and more accurate to search the network_traffic ADM than a firewall index.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jonaclough,

sorry: it isn't possible to define an automatic warning because it depends only on your specific data and it's also infruenced by other factors.

The only possible approach (for my knowledge) is the definition of a list of tips to use your data to share to all your users.

A kind of quick reference guide to use your own data.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @jonaclough,

sorry: it isn't possible to define an automatic warning because it depends only on your specific data and it's also infruenced by other factors.

The only possible approach (for my knowledge) is the definition of a list of tips to use your data to share to all your users.

A kind of quick reference guide to use your own data.

Ciao.

Giuseppe

jonaclough
Path Finder

If admission rules had an extra rule action option "issue warning" rather than just "filter search" that would do the job. 

0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...