Alerting
Highlighted

Alert - Field no longer reporting data.

New Member

Is there a way to make an alert when a interesting field is no longer sending data?

0 Karma
Highlighted

Re: Alert - Field no longer reporting data.

Ultra Champion
index=your_index interestingField="*"

To fire alert, eventcount=0

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.