Splunk Search

How to display warning based on SPL?

jonaclough
Path Finder

Is there a way of showing a warning to the user based on their SPL.

My use case is that users should not generally search indexes which are fed into an accelerated data model. Specifically it's faster and more accurate to search the network_traffic ADM than a firewall index.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jonaclough,

sorry: it isn't possible to define an automatic warning because it depends only on your specific data and it's also infruenced by other factors.

The only possible approach (for my knowledge) is the definition of a list of tips to use your data to share to all your users.

A kind of quick reference guide to use your own data.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @jonaclough,

sorry: it isn't possible to define an automatic warning because it depends only on your specific data and it's also infruenced by other factors.

The only possible approach (for my knowledge) is the definition of a list of tips to use your data to share to all your users.

A kind of quick reference guide to use your own data.

Ciao.

Giuseppe

jonaclough
Path Finder

If admission rules had an extra rule action option "issue warning" rather than just "filter search" that would do the job. 

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...