Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

i want create alert when status will be change hear hear same status will come multiple time it will ignore the after first event if differt will it will raise an alert

$
0
0
Actual requirement is when status field values are changed from one to another alert needs to be triggered below are the status field values Extended recovery Investigation suspended False positive Investigating Service degradation Service restored Restoring service Post-incident report published Ex: if status field value from false positive to investigating then alert should be triggered If field value false positive to false positive then no alert should be triggered.

Viewing all articles
Browse latest Browse all 47296

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>