Open RituSh opened 10 years ago
-------Splunk methods-----
<>You can enable the following alert actions: -Send email notification. The email notification can include information related to the alert. -Run scripts. -Enable RSS notification for the alert. -Enable summary indexing for alerts. -Track the alert in Splunk Enterprise Settings.
<>Method to edit a search string for an alert is the following: -Go the Alerts page. -Select Open in Search for the alert you want to modify. -Modify the Search. -Run the Search. -Select Save.
------------Email Notification Contexts------------- There are several contexts from which you can send email notifications. The email options available differ, depending on the context. -Alert actions: Send email notifications as an alert action from a search. Specify the notification from the Search Page, a listing in the Alerts Page, or directly from the search command. -Scheduled report: Configure email notifications for a scheduled report either from a listing in the Reports Page or from a report. -Scheduled PDF delivery of dashboards : Configure PDF delivery either from a listing in the Dashboards Page or from a dashboard.
Accpetance Criteria: -Turn searches into real-time alerts and automatically trigger notifications via email or RSS, execute remedial actions, send an SNMP trap to your system management console or generate a ticket at a service desk. -Alerts can be triggered based on a variety of thresholds, trend-based conditions and other complex searches. -Gain additional information at the time of the alert to assist with faster root cause analysis and problem resolution.