- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
anandhalagaras1
Contributor
10-16-2020
06:38 AM
Hi Team,
I want to schedule an alert something like there is no event for a particular index for more than 15 minutes it should trigger an email notification to our team.
For example: Index= os
So kindly help with the query is setting up the same.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gcusello

SplunkTrust
10-16-2020
07:19 AM
Hi @anandhalagaras1,
you should schedule an alert, tu run every 15 minutes, running a search like this:
index=os earliest=-15m@m latest=now
that has as activation condition results=0ans as action send email.
In other words:
- run the above search,
- click on "Save as Alert",
- insert the informations requested:
- cron */15 * * * *
- activation for results=0
- action=send eMail.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gcusello

SplunkTrust
10-16-2020
07:19 AM
Hi @anandhalagaras1,
you should schedule an alert, tu run every 15 minutes, running a search like this:
index=os earliest=-15m@m latest=now
that has as activation condition results=0ans as action send email.
In other words:
- run the above search,
- click on "Save as Alert",
- insert the informations requested:
- cron */15 * * * *
- activation for results=0
- action=send eMail.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gcusello

SplunkTrust
10-27-2020
12:20 AM
Hi @anandhalagaras1,
good for you!
Ciao and happy splunking.
Giuseppe
P.S.: Karma Points are appreciated 😉
