Splunk Search

Logging events on alerting?

11v
New Member

Hi Team,

working on how to log individual rows in my search result table as individual events in Splunk. Below is a picture of log events and what i'm trying to do with them.



11v_0-1676959584229.png

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could include a collect command in your alert search. (There doesn't appear to be a way to do it through the alert actions interface (unlike sending e-mails for individual rows).)

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...