Building alerts via a configuration file

As alerts are just extensions of Splunk searches, the underlying configuration details related to an alert are written to the app's local directory in a file named savedsearches.conf alongside the search.

The savedsearches.conf file for our Operational Intelligence application is located at $SPLUNK_HOME$/etc/apps/operational_intelligence/local/savedsearches.conf.

If you open this file, you will see entries related to the two searches and alerts you have created in this chapter up to now. Notice all the additional configuration fields that specify the alert criteria. If you were to copy and paste one of the searches and all the fields, but give it a new name ([name]), it would create a duplicate alert ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.