<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexes have stopped logging query/alert in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-have-Indexes-stopped-logging-query-alert/m-p/614534#M106336</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;You have two options:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Use some apps like TrackMe&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4621/" target="_blank"&gt;https://splunkbase.splunk.com/app/4621/&lt;/A&gt;&amp;nbsp;or Meta Woot&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/2949/" target="_blank"&gt;https://splunkbase.splunk.com/app/2949/&lt;/A&gt;&amp;nbsp;which can do this and lot more&lt;/LI&gt;&lt;LI&gt;Use your own SPL like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; has instructed on&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Alerting/How-to-trigger-an-alert-if-status-event-is-not-indexed-for-5/m-p/368292" target="_blank"&gt;https://community.splunk.com/t5/Alerting/How-to-trigger-an-alert-if-status-event-is-not-indexed-for-5/m-p/368292&lt;/A&gt;&amp;nbsp;(and couple of other answers &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 11:28:28 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-09-26T11:28:28Z</dc:date>
    <item>
      <title>Why have Indexes stopped logging query/alert?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-have-Indexes-stopped-logging-query-alert/m-p/614532#M106334</link>
      <description>&lt;P&gt;Hi - I am trying to run the below query to help create an alert that will show when we haven't had an alert for a particular index after 15 minutes. I need to make it so it only includes specific indexes rather than all the indexes within Splunk but can't seem to get it right. Any help on how to fix it or letting me know if there is a better way to do this would be massively appreciated!&lt;/P&gt;
&lt;P&gt;| tstats latest(_time) as latest where index=* earliest=-24hr by index | eval recent = if(latest &amp;gt; relative_time(now(),"-15m"),1,0), realLatest = strftime(latest,"%c") | rename realLatest as "Last Log" | where recent=0&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 15:39:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-have-Indexes-stopped-logging-query-alert/m-p/614532#M106334</guid>
      <dc:creator>Sion2233</dc:creator>
      <dc:date>2022-09-26T15:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes have stopped logging query/alert</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-have-Indexes-stopped-logging-query-alert/m-p/614534#M106336</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;You have two options:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Use some apps like TrackMe&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4621/" target="_blank"&gt;https://splunkbase.splunk.com/app/4621/&lt;/A&gt;&amp;nbsp;or Meta Woot&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/2949/" target="_blank"&gt;https://splunkbase.splunk.com/app/2949/&lt;/A&gt;&amp;nbsp;which can do this and lot more&lt;/LI&gt;&lt;LI&gt;Use your own SPL like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; has instructed on&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Alerting/How-to-trigger-an-alert-if-status-event-is-not-indexed-for-5/m-p/368292" target="_blank"&gt;https://community.splunk.com/t5/Alerting/How-to-trigger-an-alert-if-status-event-is-not-indexed-for-5/m-p/368292&lt;/A&gt;&amp;nbsp;(and couple of other answers &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 11:28:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-have-Indexes-stopped-logging-query-alert/m-p/614534#M106336</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-09-26T11:28:28Z</dc:date>
    </item>
  </channel>
</rss>

