<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alerts when indexing stops in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538518#M10193</link>
    <description>&lt;P&gt;Hi. I don't use real time alerting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try scheduled. For real-time I can't see the conditions when it would alert.&lt;/P&gt;&lt;P&gt;I will attach to typical kinds of alerting I do (oh only allowed on attachment per reply)..&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Either when the result count is greater than 0 (see attachment)&lt;/LI&gt;&lt;LI&gt;A field has some particular value (for that I do custom and then in the box I literally say&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;LI-CODE lang="markup"&gt;search myfield &amp;gt; 3&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Feb 2021 20:31:31 GMT</pubDate>
    <dc:creator>burwell</dc:creator>
    <dc:date>2021-02-03T20:31:31Z</dc:date>
    <item>
      <title>Alerts when indexing stops</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538299#M10183</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am a noob at Splunk. I know there are a few posts on this already but I'm not able to find a solution for my specific problem. I want to make an alert for when indexing stops. I am using the following:&amp;nbsp;| tstats latest(_time) as latest where index=* by host | where latest &amp;lt; relative_time(now(), "-1m")&lt;/P&gt;&lt;P&gt;Normally, I want the "-1m" to be "-1d" but i changed it to test the alert. I can see on the search that I have a result from an ip address that is not indexing events every minute so I know the search is working. When I save it as an alert however, I get no alerts. I have tried real-time and scheduled alerts to attempts a trigger.&lt;/P&gt;&lt;P&gt;Does anyone know why the alert doesnt work or if there is something off with the search I am trying to use?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 15:44:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538299#M10183</guid>
      <dc:creator>gba8912</dc:creator>
      <dc:date>2021-02-02T15:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts when indexing stops</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538380#M10187</link>
      <description>&lt;P&gt;Hi do you want to share exactly how you are setting up the alert condition and what are you using to alert? Can you check the _internal index for errors?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 06:48:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538380#M10187</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2021-02-03T06:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts when indexing stops</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538512#M10191</link>
      <description>&lt;P&gt;Hi Burwell,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply. I have searched _internal and have 1,136,041 events. I don't really see any errors but maybe I don't know what to look for. Also, I am using the search I posted and saving it as an alert. I have attached a screenshot of the settings that I currently have. I have also tried using the scheduled time feature. Neither works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 19:55:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538512#M10191</guid>
      <dc:creator>gba8912</dc:creator>
      <dc:date>2021-02-03T19:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts when indexing stops</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538516#M10192</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228952"&gt;@gba8912&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;tstats searches cannot run in realtime. You should change your alert schedule to "Scheduled".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 20:23:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538516#M10192</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-03T20:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts when indexing stops</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538518#M10193</link>
      <description>&lt;P&gt;Hi. I don't use real time alerting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try scheduled. For real-time I can't see the conditions when it would alert.&lt;/P&gt;&lt;P&gt;I will attach to typical kinds of alerting I do (oh only allowed on attachment per reply)..&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Either when the result count is greater than 0 (see attachment)&lt;/LI&gt;&lt;LI&gt;A field has some particular value (for that I do custom and then in the box I literally say&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;LI-CODE lang="markup"&gt;search myfield &amp;gt; 3&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 20:31:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538518#M10193</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2021-02-03T20:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts when indexing stops</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538644#M10198</link>
      <description>&lt;P&gt;Thanks! I was able to get the alerts to work with scheduled.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 16:27:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-when-indexing-stops/m-p/538644#M10198</guid>
      <dc:creator>gba8912</dc:creator>
      <dc:date>2021-02-04T16:27:25Z</dc:date>
    </item>
  </channel>
</rss>

