Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to use collect in an alert

$
0
0
i have an alert that send email to my id when the event is triggered. I also want the same alert to dump the data into my summary index. I added | collect index=sumindex at the end of my alert. Alert still works and fires email, but is not writing anything to the summary index. Can anyone help me where I am wrong or has a better way.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>