<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alerts: Getting Multiple Values into Alert in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218901#M3971</link>
    <description>&lt;P&gt;it worked as needed, thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2015 11:19:39 GMT</pubDate>
    <dc:creator>vinodmadaan</dc:creator>
    <dc:date>2015-09-28T11:19:39Z</dc:date>
    <item>
      <title>Alerts: Getting Multiple Values into Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218897#M3967</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;

&lt;P&gt;I am not sure if this has been asked before (as I couldn't find anything on this issue).&lt;/P&gt;

&lt;P&gt;I am working on a issue in which I have to create an alert for the thread count from 6 different servers, they come in as different log entries into splunk. So what I am looking for is a way to get these 6 values into the alert and trigger if any of these 6 crosses the threshold (one of the possible solution is creating 6 alerts and keeping track of each server separately, but I am looking for a way to get this done through one Alert only).&lt;/P&gt;

&lt;P&gt;Is it possible?&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2015 15:45:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218897#M3967</guid>
      <dc:creator>vinodmadaan</dc:creator>
      <dc:date>2015-09-10T15:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts: Getting Multiple Values into Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218898#M3968</link>
      <description>&lt;P&gt;Do the Threadcount from these 6 servers (assuming they are forwarders) go to central indexer(s)? &lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2015 16:24:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218898#M3968</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-09-10T16:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts: Getting Multiple Values into Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218899#M3969</link>
      <description>&lt;P&gt;Index=$yourindex host=host1 OR host=host2 OR host=host3 OR host=host4 OR host=host5 OR host=host6 $everythingelsetofindthethreaddata | stats max(Threads) as "maxthreads" by host | search "maxthreads"&amp;gt; $threshold&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2015 16:41:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218899#M3969</guid>
      <dc:creator>rechteklebe</dc:creator>
      <dc:date>2015-09-10T16:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts: Getting Multiple Values into Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218900#M3970</link>
      <description>&lt;P&gt;yes they go to a central indexer.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 07:28:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218900#M3970</guid>
      <dc:creator>vinodmadaan</dc:creator>
      <dc:date>2015-09-11T07:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts: Getting Multiple Values into Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218901#M3971</link>
      <description>&lt;P&gt;it worked as needed, thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 11:19:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-Getting-Multiple-Values-into-Alert/m-p/218901#M3971</guid>
      <dc:creator>vinodmadaan</dc:creator>
      <dc:date>2015-09-28T11:19:39Z</dc:date>
    </item>
  </channel>
</rss>

