<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log inactivity in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Log-inactivity/m-p/47804#M12168</link>
    <description>&lt;P&gt;Yes. Search for your sourcetype, save the search and create an alert from it, scheduled to run every 10 minutes. This is covered in the manual here: &lt;A href="http://www.splunk.com/base/Documentation/latest/User/SchedulingSavedSearches"&gt;http://www.splunk.com/base/Documentation/latest/User/SchedulingSavedSearches&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;As alert criteria, choose that the number of events for your search should equal 0. If no events are recorded in the 10 minutes between the scheduled searches, the alert will be triggered.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jul 2011 12:19:46 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2011-07-25T12:19:46Z</dc:date>
    <item>
      <title>Log inactivity</title>
      <link>https://community.splunk.com/t5/Alerting/Log-inactivity/m-p/47803#M12167</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;Is there a way to send an alert if there is no logs coming for more than 10min for a source type.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Harish&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2011 10:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Log-inactivity/m-p/47803#M12167</guid>
      <dc:creator>harishd</dc:creator>
      <dc:date>2011-07-25T10:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Log inactivity</title>
      <link>https://community.splunk.com/t5/Alerting/Log-inactivity/m-p/47804#M12168</link>
      <description>&lt;P&gt;Yes. Search for your sourcetype, save the search and create an alert from it, scheduled to run every 10 minutes. This is covered in the manual here: &lt;A href="http://www.splunk.com/base/Documentation/latest/User/SchedulingSavedSearches"&gt;http://www.splunk.com/base/Documentation/latest/User/SchedulingSavedSearches&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;As alert criteria, choose that the number of events for your search should equal 0. If no events are recorded in the 10 minutes between the scheduled searches, the alert will be triggered.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2011 12:19:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Log-inactivity/m-p/47804#M12168</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-07-25T12:19:46Z</dc:date>
    </item>
  </channel>
</rss>

