<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trigger a query when an alert is triggered in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-trigger-a-query-when-an-alert-is-triggered/m-p/585474#M13490</link>
    <description>&lt;P&gt;Build the growth calculation into the alert search such that the alert is only triggered based on both the backlog and the growth&lt;/P&gt;</description>
    <pubDate>Thu, 17 Feb 2022 06:55:46 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-02-17T06:55:46Z</dc:date>
    <item>
      <title>How to trigger a query when an alert is triggered</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-trigger-a-query-when-an-alert-is-triggered/m-p/585470#M13489</link>
      <description>&lt;P&gt;My requirement is to get the rate of change of a certain parameter if its corresponding alert gets triggered.&lt;BR /&gt;To add more details, we have a log file that logs the backlog of database. Once the backlog crosses a certain threshold we trigger an alert, however it could be a false positive since the system may be undergoing maintenance and hence backlog grows.&lt;BR /&gt;So I want the alert to trigger another query that captures rate of growth over the last 'x' hours.&lt;BR /&gt;This will give more context about what is happening in the system.&lt;BR /&gt;How to achieve this in splunk? Please share your ideas&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 16:03:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-trigger-a-query-when-an-alert-is-triggered/m-p/585470#M13489</guid>
      <dc:creator>ashwinve1385</dc:creator>
      <dc:date>2022-02-17T16:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger a query when an alert is triggered</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-trigger-a-query-when-an-alert-is-triggered/m-p/585474#M13490</link>
      <description>&lt;P&gt;Build the growth calculation into the alert search such that the alert is only triggered based on both the backlog and the growth&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 06:55:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-trigger-a-query-when-an-alert-is-triggered/m-p/585474#M13490</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-02-17T06:55:46Z</dc:date>
    </item>
  </channel>
</rss>

