Hi,
We are planning to create alerts based on the search pattern we are given. We are very new and need your suggestions for this.
We want to create an alert in case of any job failure. For that we used " index="3977" "Exit status 1". If we do it this way we are getting an alert email as expected.
What we are trying to do is include the job name in the email since we have 20 jobs and are not sure which alert is being triggered for which job. If we apply a separate alert as index="3977" "job_name", we are getting results but we can't track the job status from the same chunk log in Splunk, both are in separate chunks.
How can we achieve this????
... View more