Reporting

How to schedule a report to be emailed every 15 minutes that includes all syslog events since the last report?

LokiMelkoR
Explorer

Hello

I want to generate an email report on our syslog once every 15 minutes listed down with the events on that time frame. I don't want an email for every syslog.

Sort of a Rollup email that includes whatever was seen in the last 15 minutes.

EG: if 1 Syslog in last 15 minutes 1 Email with those.
10 syslogs in last 15 minutes 1 Email with those.
20 syslogs in last 15 minutes 1 Email with those

Thank you, any help much appreciated.

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Create a search over the last 15 minutes. Save it as an alert. Schedule it to run every 15 minutes.

Set it so it sends one notification per run.

alt text

View solution in original post

jkat54
SplunkTrust
SplunkTrust

Create a search over the last 15 minutes. Save it as an alert. Schedule it to run every 15 minutes.

Set it so it sends one notification per run.

alt text

LokiMelkoR
Explorer

Awesome, Thanks ! I tested it out. Works really good.

I would like to get this report to multiple syslogs. I only did for one (lets say host 'alpha') :
host = "alpha" 01070638

so lets say if i have bravo, charlie, echo.. etc. Do i use as,
host = "alpha" 01070638 or host = "bravo" 01070638 or host = "charlie" 01070638... etc. ?

0 Karma

jkat54
SplunkTrust
SplunkTrust

OR should be capitalized and the number / numerical string "01070638" you're searching for only needs to be entered once.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Like this

host=a OR host=b OR host=c 0123456789

LokiMelkoR
Explorer

Thanks again dude 🙂

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...