Files
Splunk_Docker/files/splunk-etc/apps/alert_logevent/default/restmap.conf
Brett Woodruff 28c8d411ad Inital Commit
2024-06-13 15:48:26 -04:00

4 lines
304 B
Plaintext

[validation:savedsearch]
# Require event to be set if logevent action is enabled
action.logevent = case('action.logevent' != "1", null(), 'action.logevent.param.event' == "action.logevent.param.event" OR 'action.logevent.param.event' == "", "No event text specified for log event action", 1==1, null())