<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there any way to send an email alert after a certain value? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Is-there-any-way-to-send-an-email-alert-after-a-certain-value/m-p/493723#M8779</link>
    <description>&lt;P&gt;HI @israalbo,&lt;BR /&gt;
you can create your search and when you have to save it, you can choose as options:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;an alert,&lt;/LI&gt;
&lt;LI&gt;a dashboard panel,&lt;/LI&gt;
&lt;LI&gt;a report.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;if you choose Alert, Splunk opens a panel to set the alert options (frequency, activation, etc...) and the actions (email, script  execution, etc...).&lt;/P&gt;

&lt;P&gt;For more infos see at:&lt;BR /&gt;
&lt;A href="https://www.youtube.com/watch?v=0REbozaALX0"&gt;https://www.youtube.com/watch?v=0REbozaALX0&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Aboutalerts"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Aboutalerts&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 10 Mar 2020 16:02:36 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-03-10T16:02:36Z</dc:date>
    <item>
      <title>Is there any way to send an email alert after a certain value?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-any-way-to-send-an-email-alert-after-a-certain-value/m-p/493720#M8776</link>
      <description>&lt;P&gt;I am displaying on a counter a value that basically counts the times a login has failed, but I would like to get an Email, every time that counter goes over 5, so that way I could monitor better what is going on or if it is an attack. Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 15:33:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-any-way-to-send-an-email-alert-after-a-certain-value/m-p/493720#M8776</guid>
      <dc:creator>israalbo</dc:creator>
      <dc:date>2020-03-10T15:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any way to send an email alert after a certain value?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-any-way-to-send-an-email-alert-after-a-certain-value/m-p/493721#M8777</link>
      <description>&lt;P&gt;HI @israalbo,&lt;BR /&gt;
you can use the same search to schedule an alert.&lt;BR /&gt;
You have only to define:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;frequency of execution,&lt;/LI&gt;
&lt;LI&gt;time period of search,&lt;/LI&gt;
&lt;LI&gt;threshold.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In  the alert you can also set if the alert must be fired every time there's a value that exceed threshold or if there's a period, after alert, that the alert isn't executed again.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 15:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-any-way-to-send-an-email-alert-after-a-certain-value/m-p/493721#M8777</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-03-10T15:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any way to send an email alert after a certain value?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-any-way-to-send-an-email-alert-after-a-certain-value/m-p/493722#M8778</link>
      <description>&lt;P&gt;Hi, I am new at Splunk, let me get this straight, inside the search I can get a report by email? Do you have any extra information in order to accomplish that? I would be very thankful!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 15:57:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-any-way-to-send-an-email-alert-after-a-certain-value/m-p/493722#M8778</guid>
      <dc:creator>israalbo</dc:creator>
      <dc:date>2020-03-10T15:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any way to send an email alert after a certain value?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-any-way-to-send-an-email-alert-after-a-certain-value/m-p/493723#M8779</link>
      <description>&lt;P&gt;HI @israalbo,&lt;BR /&gt;
you can create your search and when you have to save it, you can choose as options:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;an alert,&lt;/LI&gt;
&lt;LI&gt;a dashboard panel,&lt;/LI&gt;
&lt;LI&gt;a report.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;if you choose Alert, Splunk opens a panel to set the alert options (frequency, activation, etc...) and the actions (email, script  execution, etc...).&lt;/P&gt;

&lt;P&gt;For more infos see at:&lt;BR /&gt;
&lt;A href="https://www.youtube.com/watch?v=0REbozaALX0"&gt;https://www.youtube.com/watch?v=0REbozaALX0&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Aboutalerts"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Aboutalerts&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 16:02:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-any-way-to-send-an-email-alert-after-a-certain-value/m-p/493723#M8779</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-03-10T16:02:36Z</dc:date>
    </item>
  </channel>
</rss>

