You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Terraform创建Splunk告警?求最简资源配置方案

使用Terraform创建Splunk告警的最简配置

在Splunk中,告警本质是带有触发条件和动作的保存搜索,因此使用splunk_saved_searches资源即可创建告警,核心是配置告警相关参数。以下是针对splunk/splunk Terraform Provider 1.4.22版本的最简资源配置:

resource "splunk_saved_searches" "error_alert" {
  name            = "Web Server Error Alert"
  search          = "index=main sourcetype=access_combined status>=500"
  app             = "search"
  alert_type      = "number of events"
  alert_action    = "email"
  alert_threshold = 1
}

关键参数说明:

  • name:告警的唯一标识名称
  • search:用于检测告警条件的Splunk搜索语句
  • app:告警所属的Splunk应用(默认search即可)
  • alert_type:告警触发规则类型,示例中number of events表示当搜索返回的事件数达到阈值时触发
  • alert_action:告警触发后执行的动作,示例使用email(需提前在Splunk中配置邮件告警动作),也可指定其他已配置的动作如slack
  • alert_threshold:触发告警的阈值,这里设为1表示只要有1条符合条件的事件就触发

只要配置了上述alert_*系列参数,这个保存搜索就会被Splunk识别为告警,而非普通报表。

内容的提问来源于stack exchange,提问作者Brent Bradburn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 15:45:56