Alerting

Customise alerts with configurable parameters dependant on asset/app/host

ebs
Communicator

Is there a way to create a sort of catch-all base search/alert and then have customisable configurable parameters dependant on asset/app/host/criticality? If possible I'd rather not create 10s of alerts dependant on the various factors listed above but I'm not sure if there's a way to do it otherwise

 

e.g. 'too many login fails per X minutes' to have a configurable value for 'too many' depending on the asset / host /app details (i.e. we would like one use-case to cover "too many failed logins" (and other common cases) across lots of apps without copying the case over and over

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...