<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alert on Data Not Sending in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-on-Data-Not-Sending/m-p/575932#M13259</link>
    <description>&lt;P&gt;I would like to have an alert sent when my syslog server stops sending logs to the Splunk application. Because I am very new to Splunk can I get some examples please.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Nov 2021 20:37:38 GMT</pubDate>
    <dc:creator>PA-Lan-Tel</dc:creator>
    <dc:date>2021-11-22T20:37:38Z</dc:date>
    <item>
      <title>Alert on Data Not Sending</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-on-Data-Not-Sending/m-p/575932#M13259</link>
      <description>&lt;P&gt;I would like to have an alert sent when my syslog server stops sending logs to the Splunk application. Because I am very new to Splunk can I get some examples please.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 20:37:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-on-Data-Not-Sending/m-p/575932#M13259</guid>
      <dc:creator>PA-Lan-Tel</dc:creator>
      <dc:date>2021-11-22T20:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: Alert on Data Not Sending</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-on-Data-Not-Sending/m-p/575949#M13260</link>
      <description>&lt;P&gt;Very simple to write a search that you can set to trigger if the results are 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats count where index=your_syslog_index earliest=-2m@m latest=-1m@m&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then in your alert make it trigger on the custom trigger condition "search count = 0"&lt;/P&gt;&lt;P&gt;Note that if you have periods when you would not get syslog data for a minute, then it will trigger, so&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 02:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-on-Data-Not-Sending/m-p/575949#M13260</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-11-23T02:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alert on Data Not Sending</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-on-Data-Not-Sending/m-p/575999#M13262</link>
      <description>&lt;P&gt;Thanks Karma appreciate the quick response&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 09:56:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-on-Data-Not-Sending/m-p/575999#M13262</guid>
      <dc:creator>PA-Lan-Tel</dc:creator>
      <dc:date>2021-11-23T09:56:43Z</dc:date>
    </item>
  </channel>
</rss>

