<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alert when No data received on index more than 24 hours in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-when-No-data-received-on-index-more-than-24-hours/m-p/574039#M13202</link>
    <description>&lt;P&gt;Good Morning, I am trying to create an alert to indicate that data has stopped flowing to a specific index and host after 24 hours, once created, the alert would continuously trigger. but only alerted after a new occurrence of data was received.&lt;/P&gt;&lt;P&gt;My current settings for my alert are as follows:&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;Settings&lt;/P&gt;&lt;DIV class=""&gt;Alert&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Safelnk DOM East - No Data &amp;gt; 24 hours&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Description&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Search&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;|&lt;/SPAN&gt; &lt;SPAN class=""&gt;metadata&lt;/SPAN&gt; &lt;SPAN class=""&gt;type&lt;/SPAN&gt;&lt;SPAN class=""&gt;=&lt;/SPAN&gt;hosts &lt;SPAN class=""&gt;index&lt;/SPAN&gt;&lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN class=""&gt;"index Hidden"&lt;/SPAN&gt; &lt;SPAN class=""&gt;|&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;where&lt;/SPAN&gt; host=&lt;SPAN class=""&gt;"Hostname_Hidden"&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;|&lt;/SPAN&gt; &lt;SPAN class=""&gt;eval&lt;/SPAN&gt; age=&lt;SPAN class=""&gt;abs&lt;/SPAN&gt;((recentTime-&lt;SPAN class=""&gt;now&lt;/SPAN&gt;())) &lt;SPAN class=""&gt;|&lt;/SPAN&gt; &lt;SPAN class=""&gt;where&lt;/SPAN&gt; age&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt;&lt;SPAN class=""&gt;86400&lt;/SPAN&gt;&lt;SPAN class=""&gt;|&lt;/SPAN&gt; &lt;SPAN class=""&gt;table&lt;/SPAN&gt; host recentTime age &lt;SPAN class=""&gt;|&lt;/SPAN&gt; &lt;SPAN class=""&gt;convert&lt;/SPAN&gt; &lt;SPAN class=""&gt;ctime&lt;/SPAN&gt;(recentTime)&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Scheduled:&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;run everyday&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;At:&lt;/SPAN&gt;&lt;DIV class=""&gt;10:00&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Expires:&lt;DIV class=""&gt;&lt;DIV class=""&gt;999&lt;/DIV&gt;&lt;DIV class=""&gt;hour(s)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;Trigger Conditions&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Trigger alert when&lt;DIV class=""&gt;&lt;DIV class=""&gt;Number of Results&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;is Greater than: 0&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Trigger:&lt;DIV class=""&gt;&lt;DIV class=""&gt;Once For each result&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV class=""&gt;Throttle:&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Suppress results containing field value:&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Suppress triggering for:&lt;DIV class=""&gt;&lt;DIV class=""&gt;12&lt;/DIV&gt;&lt;DIV class=""&gt;hour(s)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;Trigger Actions:&lt;/P&gt;&lt;DIV class=""&gt;When triggered:&lt;DIV class=""&gt;Email is sent&lt;/DIV&gt;&lt;DIV class=""&gt;-------------------------------&lt;/DIV&gt;&lt;DIV class=""&gt;data that is sent when triggered:&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;BR /&gt;host&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; recentTime&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; age&lt;BR /&gt;"Hostname_Hidden"&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 11/08/2021&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 386&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 08 Nov 2021 15:21:35 GMT</pubDate>
    <dc:creator>DanWilkinson</dc:creator>
    <dc:date>2021-11-08T15:21:35Z</dc:date>
    <item>
      <title>Alert when No data received on index more than 24 hours</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-when-No-data-received-on-index-more-than-24-hours/m-p/574039#M13202</link>
      <description>&lt;P&gt;Good Morning, I am trying to create an alert to indicate that data has stopped flowing to a specific index and host after 24 hours, once created, the alert would continuously trigger. but only alerted after a new occurrence of data was received.&lt;/P&gt;&lt;P&gt;My current settings for my alert are as follows:&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;Settings&lt;/P&gt;&lt;DIV class=""&gt;Alert&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Safelnk DOM East - No Data &amp;gt; 24 hours&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Description&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Search&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;|&lt;/SPAN&gt; &lt;SPAN class=""&gt;metadata&lt;/SPAN&gt; &lt;SPAN class=""&gt;type&lt;/SPAN&gt;&lt;SPAN class=""&gt;=&lt;/SPAN&gt;hosts &lt;SPAN class=""&gt;index&lt;/SPAN&gt;&lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN class=""&gt;"index Hidden"&lt;/SPAN&gt; &lt;SPAN class=""&gt;|&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;where&lt;/SPAN&gt; host=&lt;SPAN class=""&gt;"Hostname_Hidden"&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;|&lt;/SPAN&gt; &lt;SPAN class=""&gt;eval&lt;/SPAN&gt; age=&lt;SPAN class=""&gt;abs&lt;/SPAN&gt;((recentTime-&lt;SPAN class=""&gt;now&lt;/SPAN&gt;())) &lt;SPAN class=""&gt;|&lt;/SPAN&gt; &lt;SPAN class=""&gt;where&lt;/SPAN&gt; age&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt;&lt;SPAN class=""&gt;86400&lt;/SPAN&gt;&lt;SPAN class=""&gt;|&lt;/SPAN&gt; &lt;SPAN class=""&gt;table&lt;/SPAN&gt; host recentTime age &lt;SPAN class=""&gt;|&lt;/SPAN&gt; &lt;SPAN class=""&gt;convert&lt;/SPAN&gt; &lt;SPAN class=""&gt;ctime&lt;/SPAN&gt;(recentTime)&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Scheduled:&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;run everyday&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;At:&lt;/SPAN&gt;&lt;DIV class=""&gt;10:00&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Expires:&lt;DIV class=""&gt;&lt;DIV class=""&gt;999&lt;/DIV&gt;&lt;DIV class=""&gt;hour(s)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;Trigger Conditions&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Trigger alert when&lt;DIV class=""&gt;&lt;DIV class=""&gt;Number of Results&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;is Greater than: 0&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Trigger:&lt;DIV class=""&gt;&lt;DIV class=""&gt;Once For each result&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV class=""&gt;Throttle:&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Suppress results containing field value:&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Suppress triggering for:&lt;DIV class=""&gt;&lt;DIV class=""&gt;12&lt;/DIV&gt;&lt;DIV class=""&gt;hour(s)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;Trigger Actions:&lt;/P&gt;&lt;DIV class=""&gt;When triggered:&lt;DIV class=""&gt;Email is sent&lt;/DIV&gt;&lt;DIV class=""&gt;-------------------------------&lt;/DIV&gt;&lt;DIV class=""&gt;data that is sent when triggered:&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;BR /&gt;host&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; recentTime&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; age&lt;BR /&gt;"Hostname_Hidden"&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 11/08/2021&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 386&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 08 Nov 2021 15:21:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-when-No-data-received-on-index-more-than-24-hours/m-p/574039#M13202</guid>
      <dc:creator>DanWilkinson</dc:creator>
      <dc:date>2021-11-08T15:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Alert when No data received on index more than 24 hours</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-when-No-data-received-on-index-more-than-24-hours/m-p/574145#M13203</link>
      <description>&lt;P&gt;Take a look at the TrackMe app&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4621/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/4621/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It has some neat features for this type of alerting and the throttling/suppression may work in your case.&lt;/P&gt;&lt;P&gt;An alternative would be to store the alerted state in a lookup, which you then check as part of your search each time the alert runs which then will not alert again until the state shows no alert active. You could have a saved search that clears the state when data is seen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 07:16:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-when-No-data-received-on-index-more-than-24-hours/m-p/574145#M13203</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-11-09T07:16:46Z</dc:date>
    </item>
  </channel>
</rss>

