Alerts Flashcards
When is an alert triggered?
When a search meets a specific condition
List 5 functions of alerts
List in interface Log Events Send Emails Trigger Scripts Use a webhook run a custom script
A serach string such as sourcetype=access_combined_wcookie status=5*
can be saved as an alert. True or False
True, from the save as alert menu
What are the 2 permissions on an alert?
Private (only you can access/edit/view)
Share in App (results will display to all users of the app)
What are the 2 different types of alerts and what do they do?
Scheduled (set a scheduled time range for search to be run - predefined or expressed) Real Time (will run continously int he background (more overhead on performance)
How can see triggered alerts
Via the Activity menu and triggered alerts
What is an alert
an action triggered by a saved search
What can an alert do?
Add to triggered alerts
User a log event action (send to splunk for deployment indexing)
Run a script (triggers shell script or batch file)
Send email (set where to send email, priority, subject and message)
webhooks (define customer hoobacks, create alert in chatroom or create ticket in helpsdesk system)