<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Alerting in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542785#M10287</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232219"&gt;@praneethlekkala&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it's easy:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;open the app where you want to locate your alert,&lt;/LI&gt;&lt;LI&gt;open search form,&lt;/LI&gt;&lt;LI&gt;run your search, using the time range you want in the alert (e.g. last 30 minutes),&lt;/LI&gt;&lt;LI&gt;click on "Save as" and then "Alert",&lt;/LI&gt;&lt;LI&gt;insert the infos requested in the form:&lt;UL&gt;&lt;LI&gt;alert title,&lt;/LI&gt;&lt;LI&gt;permissions "Shared in App",&lt;/LI&gt;&lt;LI&gt;scheduled: "Run on cron schedule",&lt;/LI&gt;&lt;LI&gt;check the Time Range,&lt;/LI&gt;&lt;LI&gt;use the correct cron schedule: */30 * * * *&lt;/LI&gt;&lt;LI&gt;Number of results=0&lt;/LI&gt;&lt;LI&gt;Trigger once,&lt;/LI&gt;&lt;LI&gt;throttle (if you want to disable your alert for a period after triggering),&lt;/LI&gt;&lt;LI&gt;Add action:&lt;UL&gt;&lt;LI&gt;Add to triggered alerts,&lt;/LI&gt;&lt;LI&gt;Send email,&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Add the infos of the alert email,&lt;/LI&gt;&lt;LI&gt;save it.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 08 Mar 2021 07:22:35 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-03-08T07:22:35Z</dc:date>
    <item>
      <title>Splunk Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542783#M10286</link>
      <description>&lt;P&gt;I am trying to create a splunk alert, which sends an email if a key value is missing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;host="myhost" sourcetype="access_log" "Key_Word in the access logs'"&lt;/P&gt;&lt;P&gt;Usually i get the log entries every 30 mins, i want to get alerted via an email if "Key_Word in the access logs" is missing from the access logs, can someone guide me on this?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 07:07:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542783#M10286</guid>
      <dc:creator>praneethlekkala</dc:creator>
      <dc:date>2021-03-08T07:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542785#M10287</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232219"&gt;@praneethlekkala&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it's easy:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;open the app where you want to locate your alert,&lt;/LI&gt;&lt;LI&gt;open search form,&lt;/LI&gt;&lt;LI&gt;run your search, using the time range you want in the alert (e.g. last 30 minutes),&lt;/LI&gt;&lt;LI&gt;click on "Save as" and then "Alert",&lt;/LI&gt;&lt;LI&gt;insert the infos requested in the form:&lt;UL&gt;&lt;LI&gt;alert title,&lt;/LI&gt;&lt;LI&gt;permissions "Shared in App",&lt;/LI&gt;&lt;LI&gt;scheduled: "Run on cron schedule",&lt;/LI&gt;&lt;LI&gt;check the Time Range,&lt;/LI&gt;&lt;LI&gt;use the correct cron schedule: */30 * * * *&lt;/LI&gt;&lt;LI&gt;Number of results=0&lt;/LI&gt;&lt;LI&gt;Trigger once,&lt;/LI&gt;&lt;LI&gt;throttle (if you want to disable your alert for a period after triggering),&lt;/LI&gt;&lt;LI&gt;Add action:&lt;UL&gt;&lt;LI&gt;Add to triggered alerts,&lt;/LI&gt;&lt;LI&gt;Send email,&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Add the infos of the alert email,&lt;/LI&gt;&lt;LI&gt;save it.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 07:22:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542785#M10287</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-08T07:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542787#M10288</link>
      <description>&lt;P&gt;Check below docs:&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/Alert/Emailnotification" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/Alert/Emailnotification&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/Alert/EmailNotificationTokens" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/Alert/EmailNotificationTokens&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 07:25:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542787#M10288</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-03-08T07:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542819#M10290</link>
      <description>&lt;P&gt;Thanks!! let me try this..&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 12:21:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542819#M10290</guid>
      <dc:creator>praneethlekkala</dc:creator>
      <dc:date>2021-03-08T12:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542820#M10291</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 12:22:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542820#M10291</guid>
      <dc:creator>praneethlekkala</dc:creator>
      <dc:date>2021-03-08T12:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542961#M10303</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232219"&gt;@praneethlekkala&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 07:57:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerting/m-p/542961#M10303</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-09T07:57:40Z</dc:date>
    </item>
  </channel>
</rss>

