Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to create an alert that triggers when field value status changes?

$
0
0
Actual requirement is when a status field value changes from one to another, an alert needs to be triggered. Below are the status field values: Extended recovery Investigation suspended False-positive Investigating Service degradation Service restored Restoring service Post-incident report published Ex: If status field value changes from "false-positive" to "investigating" then alert should be triggered. If field value changes from "false-positive" to "false-positive" then no alert should be triggered.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>