Splunk Search

lookuptable compare with new event

Satsan
Engager

I called all the errors and created to lookup-table. I want to create a job which would compare the last 5 minutes of errors with errors in lookup-table . If it doesn't match it would trigger an alert ( means finding new error from existing)

Can we do this via Splunk query ? , if so can you please share the sample query

0 Karma

Shan
Builder

@Satsan,

Give a try with below answer..
You need to get the values from index which are not already available in lookup already. So when you get a new error alert can be triggered.

https://answers.splunk.com/answers/426035/search-for-items-not-matching-values-from-a-lookup-1.html

0 Karma

Satsan
Engager

Thank you, i will go ahead and try

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...