Splunk Search

Splunk rules and their way how it is configured

Umamaheshwar210
New Member

Hi ,

We are using Splunk 6.1.1 Ver .I would like to know few Information from Splunk.

Their are alerts configured in Splunk So my interest is to know more information about those alerts and the IP address which are configured in those alerts.As simple as I would like to know the rules that triggers the alerts on Splunk and the configuration.

Tags (1)
0 Karma

vinodmadaan
Path Finder

Hi Umam,

I guess you need to know how you can configure the Alerts through the config file, The following link shows the scripts and rules that we follow to do the same:

http://docs.splunk.com/Documentation/Splunk/6.2.1/Alert/Configuringalertsinsavedsearches.conf

I hope this answer's your question.

Vinod.

0 Karma

kendrickt
Path Finder

Hi Umam,

I'm not 100% sure what you mean, but "alerts" are completely configurable by the user - so you get it to alert you in a method you choose according to a trigger you set.

Take a look at this:

http://docs.splunk.com/Documentation/Splunk/6.1.1/Alert/Alertexamples

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...