Splunk Search

Logging events on alerting?

11v
New Member

Hi Team,

working on how to log individual rows in my search result table as individual events in Splunk. Below is a picture of log events and what i'm trying to do with them.



11v_0-1676959584229.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could include a collect command in your alert search. (There doesn't appear to be a way to do it through the alert actions interface (unlike sending e-mails for individual rows).)

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...