Alerting

Customise alerts with configurable parameters dependant on asset/app/host

ebs
Communicator

Is there a way to create a sort of catch-all base search/alert and then have customisable configurable parameters dependant on asset/app/host/criticality? If possible I'd rather not create 10s of alerts dependant on the various factors listed above but I'm not sure if there's a way to do it otherwise

 

e.g. 'too many login fails per X minutes' to have a configurable value for 'too many' depending on the asset / host /app details (i.e. we would like one use-case to cover "too many failed logins" (and other common cases) across lots of apps without copying the case over and over

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...

Secure Your Future: Mastering Upgrade Readiness for Splunk 10

Spotlight: The Splunk Health Assistant Add-On  The Splunk Health Assistant Add-On is your ultimate companion ...

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...