Hi Team,
I want to schedule an alert something like there is no event for a particular index for more than 15 minutes it should trigger an email notification to our team.
For example: Index= os
So kindly help with the query is setting up the same.
Hi @anandhalagaras1,
you should schedule an alert, tu run every 15 minutes, running a search like this:
index=os earliest=-15m@m latest=now
that has as activation condition results=0ans as action send email.
In other words:
Ciao.
Giuseppe
Hi @anandhalagaras1,
you should schedule an alert, tu run every 15 minutes, running a search like this:
index=os earliest=-15m@m latest=now
that has as activation condition results=0ans as action send email.
In other words:
Ciao.
Giuseppe
Hi @anandhalagaras1,
good for you!
Ciao and happy splunking.
Giuseppe
P.S.: Karma Points are appreciated 😉