Hi,
I potentially want to set a scheduled search - where i specify the list of exceptions in the search - and if there is any new exception outside of those listed exceptions, Splunk should send an email alert.
For example:
Consider, here is my list of exceptions:
"error: null pointer exception (login.class:1494)"
"error: database down exception (database.class:1594)"
"error: read PFD (readPDF.class:1694)"
Now, whenever there is a new exception generated (outside of those listed above), Splunk sends me alert.
Thanks for looking into this.
Usman Chaudhri
... View more