Splunk | Configure alerts
Perform the following steps to configure alerts for your Splunk instance.
To configure alerts:
-
Enter the following query into the Splunk search field. Change the values between square brackets [] to the appropriate values for you instance.
Copyindex=[companyindex] Primary.methodName="[Monitor Name]"
"Primary.testStatus"=Fail | rename Primary.description as "Device Description",
Primary.reportiumReport as "Primary Report",
Primary.location as "Primary Device Location",
Primary.methods." [Monitor Name]".Steps{}.step as "Primary Transactions",
Primary.methods." [Monitor Name]".Steps{}.stepStatus as "Primary Status",
primary.methodName as Monitor | strcat "[Customer Interactive Cloud Device URL]"
Primary.device DeviceLink1 | table "Device Description" "Primary Device Location" "Primary Transactions" "Primary Status"
DeviceLink1 "Primary Report" -
On the right side of the search bar, click the down arrow to set the time period to the last 60 minutes.
-
Click the spy glass search button to submit the search.
-
Save the result as a report with a meaningful name, as follows:
-
Click Save As.
-
From the drop-down menu, choose Report.
-
Save the same result as an Alert from the same-drop down menu.
-
Complete fields in the Alert dialog as suggested below.
- Title - [Name of Alert]
- Description – Optional
- Permissions – Shared in App
- Alert Type – Real Time
- Trigger alert when – Number of Results
- Is greater than – [choose a number of results as needed]
- In – Choose a time period to limit the results to
-
Trigger – Choose either a single alert or once for each occurrence.
-
Throttle – Check to suppress subsequent alerts for the throttle period.
a. Suppress results containing field value - A field value can be added to filter alerts to be suppressed.
b. Suppress triggering for - Define a time period for suppressing alerts
-
- Trigger actions:
Click Add Actions.
Choose Send email.
Configure email with suggested settings below:
To [recipient emails]
Email Priority – as needed
Subject – can be left as default or edited
Message – Can be left as default. Additional fields can be added by using the token in this format “$result.[field]$”
Include desired elements as suggested below
For Table in email with links to reports, check Inline Table
Type – HTML & Plain Text
Click Save
Test alert conditions by either waiting for or creating a failure. An email should be sent to recipients containing a table as was shown in the search results.