Skip to content

Instantly share code, notes, and snippets.

@JasonConger
Last active August 29, 2015 14:22
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save JasonConger/3c331c6eab6998780a76 to your computer and use it in GitHub Desktop.
Save JasonConger/3c331c6eab6998780a76 to your computer and use it in GitHub Desktop.
Splunk Octoblu Alert Search
[ICA RTT - Yellow]
action.email.reportServerEnabled = 0
action.email.useNSSubject = 1
action.script = 1
action.script.filename = octoblu_trigger.py
alert.digest_mode = True
alert.suppress = 1
alert.suppress.period = 1m
alert.track = 0
counttype = number of events
cron_schedule = * * * * *
dispatch.earliest_time = rt
dispatch.latest_time = rt
display.general.type = statistics
display.page.search.tab = statistics
display.visualizations.charting.chart = radialGauge
enableSched = 1
quantity = 0
relation = greater than
request.ui_dispatch_app = octoblu
request.ui_dispatch_view = search
search = sourcetype="ICA:RTT" ICARTT > 30 ICARTT < 60 | eval url="your Octoblu trigger URL" | eval alert_level="Yellow"
disabled = 0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment