Alerting

How an alert can be raised separately for each event/result returned by a saved search?

AditiKulkarni
New Member

I have a saved search which returns multiple results/events at a time. I have configured this saved search to raise a real-time alert. I want the alert to be raised separately for each of the events returned by saved search for which i have set the alert mode as "Per result", but it is not giving the expected results. It is raising only a single alert for all of the events returned by the saved search at a time.

My scenario is: My saved search returns R1, R2, R3, ..., Rn results at a time. I want the alert to be raised separately for each of the results, say alert A1 for result R1, alert A2 for result R2 and so on. For this i have set an alert mode as "Per result", but the actual result I am getting is only alert A1 for all of the results R1, R2, R3,...., Rn. Could anyone help me in this? Is there any other way to achieve this?

0 Karma

bshuler_splunk
Splunk Employee
Splunk Employee
0 Karma

AditiKulkarni
New Member

Yes... I am following the exact procedure still i am getting only one alert for multiple search results and not separate alert for each of the result.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...