Splunk Search

How to search for all banner messages?

richnavis
Contributor

As part of understanding our end user experience, I'd like to create a search that tells me whenever splunk created a message that appeared as a banner message to end users. Is this possible?

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

One place to start would be this:

index=_internal source="*web_service.log" raise

You'll get events for exceptions being raised, usually that's equivalent to a red error message. Off the top of my instance I don't see blue info messages being logged though.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

One place to start would be this:

index=_internal source="*web_service.log" raise

You'll get events for exceptions being raised, usually that's equivalent to a red error message. Off the top of my instance I don't see blue info messages being logged though.

w531t4
Path Finder

Is there a definitive way to do this? Including "usually" as part of the answer isn't good enough.

0 Karma
Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...