<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Event for when a log host or source fails in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Event-for-when-a-log-host-or-source-fails/m-p/73336#M181086</link>
    <description>&lt;P&gt;Is there a way to configure an event to fire when a certain log host or source fails to send logs after a given amount of time?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2013 15:19:31 GMT</pubDate>
    <dc:creator>jasrich</dc:creator>
    <dc:date>2013-06-24T15:19:31Z</dc:date>
    <item>
      <title>Event for when a log host or source fails</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Event-for-when-a-log-host-or-source-fails/m-p/73336#M181086</link>
      <description>&lt;P&gt;Is there a way to configure an event to fire when a certain log host or source fails to send logs after a given amount of time?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2013 15:19:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Event-for-when-a-log-host-or-source-fails/m-p/73336#M181086</guid>
      <dc:creator>jasrich</dc:creator>
      <dc:date>2013-06-24T15:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: Event for when a log host or source fails</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Event-for-when-a-log-host-or-source-fails/m-p/73337#M181087</link>
      <description>&lt;P&gt;I don't think this is going to be possible, alerting works on taking searchable data and sending an alert about its contents. If splunk doesn't have data to search from, it can't send an alert.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2013 15:24:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Event-for-when-a-log-host-or-source-fails/m-p/73337#M181087</guid>
      <dc:creator>Antioch</dc:creator>
      <dc:date>2013-06-24T15:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Event for when a log host or source fails</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Event-for-when-a-log-host-or-source-fails/m-p/73338#M181088</link>
      <description>&lt;P&gt;You could define a scheduled search that computes the number of events matching your criteria, and set an alert to trigger if that number is zero.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2013 15:44:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Event-for-when-a-log-host-or-source-fails/m-p/73338#M181088</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-06-24T15:44:10Z</dc:date>
    </item>
  </channel>
</rss>

