<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trigger condition in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Trigger-condition/m-p/667177#M15460</link>
    <description>&lt;P&gt;If you already have the search then click the "Save as" drop-down in the top-right corner of the window and choose "Alert".&amp;nbsp; The trigger condition is set in the lower part of the subsequent form.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2023 13:17:10 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-11-02T13:17:10Z</dc:date>
    <item>
      <title>Trigger condition</title>
      <link>https://community.splunk.com/t5/Alerting/Trigger-condition/m-p/667173#M15459</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a basic search, where i need to alert when particular process name not available in raw data or last 15 minutes data. Plz suggest how to get the trigger.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Vijay K.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 13:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Trigger-condition/m-p/667173#M15459</guid>
      <dc:creator>kulkarnivijay27</dc:creator>
      <dc:date>2023-11-02T13:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger condition</title>
      <link>https://community.splunk.com/t5/Alerting/Trigger-condition/m-p/667177#M15460</link>
      <description>&lt;P&gt;If you already have the search then click the "Save as" drop-down in the top-right corner of the window and choose "Alert".&amp;nbsp; The trigger condition is set in the lower part of the subsequent form.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 13:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Trigger-condition/m-p/667177#M15460</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-11-02T13:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger condition</title>
      <link>https://community.splunk.com/t5/Alerting/Trigger-condition/m-p/667178#M15461</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Splunk is not good to found something which is not existing &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Here is one blog post about it&amp;nbsp;&lt;A href="https://www.duanewaddle.com/proving-a-negative/" target="_blank" rel="noopener"&gt;https://www.duanewaddle.com/proving-a-negative/&lt;/A&gt;&amp;nbsp;maybe it helps you.&lt;/P&gt;&lt;P&gt;Other ideas could be found from these&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;There are a lot of options for finding hosts or sources that stop submitting events:&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Meta Woot!&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://splunkbase.splunk.com/app/2949/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/2949/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;TrackMe&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://splunkbase.splunk.com/app/4621/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/4621/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Broken Hosts App for Splunk&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://splunkbase.splunk.com/app/3247/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/3247/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Alerts for Splunk Admins ("ForwarderLevel" alerts)&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://splunkbase.splunk.com/app/3796/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/3796/&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Some helpful posts:&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;A class="" href="https://lantern.splunk.com/hc/en-us/articles/360048503294-Hosts-logging-data-in-a-certain-timeframe" target="_blank" rel="noopener noreferrer"&gt;https://lantern.splunk.com/hc/en-us/articles/360048503294-Hosts-logging-data-in-a-certain-timeframe&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 13:17:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Trigger-condition/m-p/667178#M15461</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-02T13:17:26Z</dc:date>
    </item>
  </channel>
</rss>

