Splunk Search

finding alerts (saved searchs) based on alarm IDs or other event contents

MarcRiese
Explorer

Usually I find an individual alert, i.e., a saved search, among a large number of alerts by searching for it by name.

How can I find the individual alert that generates a known, specific alarm-ID, e.g. "file error 12345"?

More generally, how does one find an alert, among a large number of alerts, based on the contents of the events it generates?

Is there a way to find all alerts that generate alarm IDs containing a text, i.e. where the text is a substring of the complete alarm IDs. For example, all alerts that generate alarm IDs containing "file error"?

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I'm not aware of a way to search for the alert that generated a particular set of results.

To help identify which alert generated a particular alarm, start with the Activity->Triggered Alerts page.  This way you are not checking searches that haven't fired.

It may help to include the search name in any email alerts.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

I'm not aware of a way to search for the alert that generated a particular set of results.

To help identify which alert generated a particular alarm, start with the Activity->Triggered Alerts page.  This way you are not checking searches that haven't fired.

It may help to include the search name in any email alerts.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...