Splunk Search

finding alerts (saved searchs) based on alarm IDs or other event contents

MarcRiese
Explorer

Usually I find an individual alert, i.e., a saved search, among a large number of alerts by searching for it by name.

How can I find the individual alert that generates a known, specific alarm-ID, e.g. "file error 12345"?

More generally, how does one find an alert, among a large number of alerts, based on the contents of the events it generates?

Is there a way to find all alerts that generate alarm IDs containing a text, i.e. where the text is a substring of the complete alarm IDs. For example, all alerts that generate alarm IDs containing "file error"?

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I'm not aware of a way to search for the alert that generated a particular set of results.

To help identify which alert generated a particular alarm, start with the Activity->Triggered Alerts page.  This way you are not checking searches that haven't fired.

It may help to include the search name in any email alerts.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

I'm not aware of a way to search for the alert that generated a particular set of results.

To help identify which alert generated a particular alarm, start with the Activity->Triggered Alerts page.  This way you are not checking searches that haven't fired.

It may help to include the search name in any email alerts.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...