Saving searches for reuse

Let's build a query, save it, and make an alert out of it.

First, let's find errors that affect mary, one of our most important users. This can simply be the query mary error. Looking at some sample log messages that match this query, we see that some of these events probably don't matter (the dates have been removed to shorten the lines).

  ERROR LogoutClass error, ERROR, Error! [user=mary, ip=3.2.4.5]
  WARN AuthClass error, ERROR, Error! [user=mary, ip=1.2.3.3]
  ERROR BarCLass Hello world. [user=mary, ip=4.3.2.1]
  WARN LogoutClass error, ERROR, Error! [user=mary, ip=1.2.3.4]
  DEBUG FooClass error, ERROR, Error! [user=mary, ip=3.2.4.5]
 ERROR AuthClass Nothing happened. This is worthless. Don't log this.[user=mary, ip=1.2.3.3] ...

Get Implementing Splunk: Big Data Reporting and Development for Operational Intelligence now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.