Splunk Search

How should I create a software installation alert?

msachdeva3
Explorer

Question : I'm trying to install software on some devices & if the install fails, I should know and in which step it failed?
Ideally i want to present a report/dashboard. also I would need to set up an alert.

I have data being logged for each installation step in Splunk. Mostly data in json fomrat.
it has time timestamp,device id, & install step info

what i should be reading in terms of docs & any pointers to approach the problem?

woodcock
Esteemed Legend

If the data is JSON then make sure that you use INDEXED_EXTRACTIONS=JSON. Then the fields that you need will be automatically available to you and you can just search for fieldname="fieldvalue".

0 Karma

jplumsdaine22
Influencer

If you haven't done so already I highly recommend running through the Splunk tutorial. It takes a few hours but it will give you a lot of grounding in the basics. http://docs.splunk.com/Documentation/Splunk/6.5.2/SearchTutorial/WelcometotheSearchTutorial

The tutorial should give you a good enough grounding to explore your data and will probably enable you to solve your problem. After that I would get familiar with the SPL manual http://docs.splunk.com/Documentation/Splunk/6.5.2/Search/GetstartedwithSearch and SPL reference http://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/WhatsInThisManual

Failing that, googling splunk should produce some links to peopole who have encountered your specific issue.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...