Admin Manual

 


How alerting works

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

How alerting works

Alerts are searches you've configured to run on a schedule and send you their results. Use alerts to notify you of changes in your data, network infrastructure, file system or other devices you're monitoring. Alerts can be sent via email or RSS, or trigger a shell script. You can turn any saved search into an alert.

An alert is comprised of:

Enable alerts

Set up an alert at the time you create a saved search, or enable an alert on any existing saved search you have permission to edit. Configure alerts via:

Specify overall email settings for alerts

To specify the mail host, email format, subject, sender, and whether or not the results of the alert should be included inline:

All alerts will now use these settings.

Scripted alerts

Alerts can also trigger shell scripts. When you configure an alert, specify a script you've written. You can use this feature to send alerts to other applications. Learn more about configuring scripted alerts.

You can use scripted alerts to send syslog events, or SNMP traps.

Customize alerts

Use the alert_actions.conf file to customize alert settings. For example, change email configuration (mail server, subject line, etc). Learn more about customizing alert options.

Considerations

When configuring alerts, keep the following in mind:

This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!