Splunk Search

Splunk rules and their way how it is configured

Umamaheshwar210
New Member

Hi ,

We are using Splunk 6.1.1 Ver .I would like to know few Information from Splunk.

Their are alerts configured in Splunk So my interest is to know more information about those alerts and the IP address which are configured in those alerts.As simple as I would like to know the rules that triggers the alerts on Splunk and the configuration.

Tags (1)
0 Karma

vinodmadaan
Path Finder

Hi Umam,

I guess you need to know how you can configure the Alerts through the config file, The following link shows the scripts and rules that we follow to do the same:

http://docs.splunk.com/Documentation/Splunk/6.2.1/Alert/Configuringalertsinsavedsearches.conf

I hope this answer's your question.

Vinod.

0 Karma

kendrickt
Path Finder

Hi Umam,

I'm not 100% sure what you mean, but "alerts" are completely configurable by the user - so you get it to alert you in a method you choose according to a trigger you set.

Take a look at this:

http://docs.splunk.com/Documentation/Splunk/6.1.1/Alert/Alertexamples

0 Karma
Get Updates on the Splunk Community!

Monitoring MariaDB and MySQL

In a previous post, we explored monitoring PostgreSQL and general best practices around which metrics to ...

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...