Alerts Flashcards

1
Q

When is an alert triggered?

A

When a search meets a specific condition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

List 5 functions of alerts

A
List in interface
Log Events
Send Emails
Trigger Scripts
Use a webhook
run a custom script
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A serach string such as sourcetype=access_combined_wcookie status=5*
can be saved as an alert. True or False

A

True, from the save as alert menu

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 2 permissions on an alert?

A

Private (only you can access/edit/view)

Share in App (results will display to all users of the app)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 2 different types of alerts and what do they do?

A
Scheduled (set a scheduled time range for search to be run - predefined or expressed)
Real Time (will run continously int he background (more overhead on performance)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How can see triggered alerts

A

Via the Activity menu and triggered alerts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an alert

A

an action triggered by a saved search

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What can an alert do?

A

Add to triggered alerts
User a log event action (send to splunk for deployment indexing)
Run a script (triggers shell script or batch file)
Send email (set where to send email, priority, subject and message)
webhooks (define customer hoobacks, create alert in chatroom or create ticket in helpsdesk system)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly