<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamically updated alert search in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24696#M191</link>
    <description>&lt;P&gt;If your nmap application writes one event per monitored port per minute, and you'd like to find out if the port monitoring app itself has crashed, you could simply have a scheduled search that will detect if the logs stop coming in completely. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;your source/sourcetype&amp;gt; earliest=-1m 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;with the alert triggering set on the condition "number of events = 0" &lt;/P&gt;

&lt;P&gt;Have I understood your problem correctly? Is this a viable solution?&lt;/P&gt;

&lt;P&gt;/kristian&lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2011 09:46:49 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2011-11-30T09:46:49Z</dc:date>
    <item>
      <title>Dynamically updated alert search</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24695#M190</link>
      <description>&lt;P&gt;I am running a port monitoring app using NMAP that record system availability&lt;/P&gt;

&lt;P&gt;If this stops it makes my system availability stats wrong&lt;/P&gt;

&lt;P&gt;I would like to create and alert that will tell me if this is not working.&lt;/P&gt;

&lt;P&gt;Not too hard but I would like the alert to be dynamic and adjust for the number of systems I am monitoring.&lt;/P&gt;

&lt;P&gt;Right now I have 60 systems monitored every minute so ( 60*60 ) or 3600 events per hour&lt;/P&gt;

&lt;P&gt;So I can set an alert for less than 3600 event but if I add a system, the alert should go up or ( 61*60 ) trigger = 3660 per hour&lt;/P&gt;

&lt;P&gt;How do I write the alert to have dynamic triggers?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2011 21:56:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24695#M190</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2011-11-29T21:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamically updated alert search</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24696#M191</link>
      <description>&lt;P&gt;If your nmap application writes one event per monitored port per minute, and you'd like to find out if the port monitoring app itself has crashed, you could simply have a scheduled search that will detect if the logs stop coming in completely. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;your source/sourcetype&amp;gt; earliest=-1m 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;with the alert triggering set on the condition "number of events = 0" &lt;/P&gt;

&lt;P&gt;Have I understood your problem correctly? Is this a viable solution?&lt;/P&gt;

&lt;P&gt;/kristian&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2011 09:46:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24696#M191</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2011-11-30T09:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamically updated alert search</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24697#M192</link>
      <description>&lt;P&gt;Thanks for answering I really appreciate your participation and trying to help.  I can't monitor the log inputs because some of the clients are quit for longer than a minute and I wanted to get a one minute interval to monitor availability.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2011 17:34:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24697#M192</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2011-11-30T17:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamically updated alert search</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24698#M193</link>
      <description>&lt;P&gt;Sorry, I thought you wanted to monitor availability in splunk, and also monitor the status of the monitoring application itself - and that it was the latter problem you wanted help with. I still don't know really what you want to perform. &lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2011 18:43:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24698#M193</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2011-11-30T18:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamically updated alert search</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24699#M194</link>
      <description>&lt;P&gt;I'm sorry I was looking for one kind of answer and you gave me the right one.  It was not what I expected so I thought it must be wrong.  I was looking for a way to alert on the input not the monitoring.  I have setup an alert like you have suggested above and this will do what I wanted.  Thanks for the help I really appreciate it.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2011 18:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24699#M194</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2011-12-02T18:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamically updated alert search</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24700#M195</link>
      <description>&lt;P&gt;You are most welcome&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2011 20:27:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamically-updated-alert-search/m-p/24700#M195</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2011-12-02T20:27:12Z</dc:date>
    </item>
  </channel>
</rss>

