<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: when splunk error count is more than a number in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574770#M13224</link>
    <description>&lt;P&gt;sure&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;. Thank you&lt;/P&gt;</description>
    <pubDate>Fri, 12 Nov 2021 16:29:55 GMT</pubDate>
    <dc:creator>rajs115</dc:creator>
    <dc:date>2021-11-12T16:29:55Z</dc:date>
    <item>
      <title>when splunk error count is more than a number</title>
      <link>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574653#M13217</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;I have a log file in splunk which reports the errors when ever something failed. Now i need to run a splunk query if a same error show up in Splunk more than 3 times in last 1 hour. If it happens i need to send an alert.&lt;/P&gt;&lt;P&gt;Can someone suggest me the query with time in it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 19:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574653#M13217</guid>
      <dc:creator>rajs115</dc:creator>
      <dc:date>2021-11-11T19:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: when splunk error count is more than a number</title>
      <link>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574658#M13218</link>
      <description>&lt;P&gt;Your "specification" can be interpreted in many ways &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Do you just want to search for some alert and find out if it's 3 or more events? Or maybe you can have several different kinds of alerts and want to know if any single one of them occurs more than 3 times.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 20:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574658#M13218</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-11T20:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: when splunk error count is more than a number</title>
      <link>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574659#M13219</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;"&lt;STRONG&gt;Build&amp;nbsp;failed&lt;/STRONG&gt;" is what i need to check in each event logs over the last 1 hour. If its repeated more than 3 times(from 3 events) in last 1 hour i need to send an alert. I hope you get my question now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 20:37:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574659#M13219</guid>
      <dc:creator>rajs115</dc:creator>
      <dc:date>2021-11-11T20:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: when splunk error count is more than a number</title>
      <link>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574761#M13223</link>
      <description>&lt;P&gt;Just do your search for "Build Failed" and trigger the alert when number of results is greater than 2. Easy.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 16:11:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574761#M13223</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-12T16:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: when splunk error count is more than a number</title>
      <link>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574770#M13224</link>
      <description>&lt;P&gt;sure&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;. Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 16:29:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/when-splunk-error-count-is-more-than-a-number/m-p/574770#M13224</guid>
      <dc:creator>rajs115</dc:creator>
      <dc:date>2021-11-12T16:29:55Z</dc:date>
    </item>
  </channel>
</rss>

