Splunk Search

lookuptable compare with new event

Satsan
Engager

I called all the errors and created to lookup-table. I want to create a job which would compare the last 5 minutes of errors with errors in lookup-table . If it doesn't match it would trigger an alert ( means finding new error from existing)

Can we do this via Splunk query ? , if so can you please share the sample query

0 Karma

Shan
Builder

@Satsan,

Give a try with below answer..
You need to get the values from index which are not already available in lookup already. So when you get a new error alert can be triggered.

https://answers.splunk.com/answers/426035/search-for-items-not-matching-values-from-a-lookup-1.html

0 Karma

Satsan
Engager

Thank you, i will go ahead and try

0 Karma
Get Updates on the Splunk Community!

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

💌Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...