<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating alert on if log message does not appear in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-alert-on-if-log-message-does-not-appear/m-p/653629#M225869</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I was dealt with a similar scenario.&lt;/P&gt;&lt;P&gt;I would use a lookup to get a list of servers. I would also add the threshold to the lookup (host, threshold) to future-proof it.&lt;/P&gt;&lt;P&gt;Then you can append the list and do some dudup/stats magic; or start with inputlookup and join your search.&amp;nbsp;&lt;/P&gt;&lt;P&gt;smurf&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2023 22:23:17 GMT</pubDate>
    <dc:creator>smurf</dc:creator>
    <dc:date>2023-08-08T22:23:17Z</dc:date>
    <item>
      <title>How to create alert on if log message does not appear?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-alert-on-if-log-message-does-not-appear/m-p/653626#M225868</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a splunk source which does have data ingestion from multiple servers, i want to setup an alert on that source on a specific condition that if a particular message does not appear for 6 hour alert should be triggered&lt;/P&gt;
&lt;P&gt;below is an example to search the string&lt;/P&gt;
&lt;P&gt;&amp;nbsp;index=index1 source = source1 host=host1 "got the message"&lt;/P&gt;
&lt;P&gt;so if i dont find the message "got the message" for 6 hours i want to trigger an alert .&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 16:23:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-alert-on-if-log-message-does-not-appear/m-p/653626#M225868</guid>
      <dc:creator>batham</dc:creator>
      <dc:date>2023-08-09T16:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Creating alert on if log message does not appear</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-alert-on-if-log-message-does-not-appear/m-p/653629#M225869</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I was dealt with a similar scenario.&lt;/P&gt;&lt;P&gt;I would use a lookup to get a list of servers. I would also add the threshold to the lookup (host, threshold) to future-proof it.&lt;/P&gt;&lt;P&gt;Then you can append the list and do some dudup/stats magic; or start with inputlookup and join your search.&amp;nbsp;&lt;/P&gt;&lt;P&gt;smurf&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 22:23:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-alert-on-if-log-message-does-not-appear/m-p/653629#M225869</guid>
      <dc:creator>smurf</dc:creator>
      <dc:date>2023-08-08T22:23:17Z</dc:date>
    </item>
  </channel>
</rss>

