Alerting

Alert on sourcetypes in deploymemt monitor

jbirchall1
New Member

Is it possible to sett up alerts on failed sourcetypes or hosts in deployment monitor rather than having a generic alert for all sourcetypes and having to drill down?

Tags (1)
0 Karma

MarioM
Motivator

you could clone the existing search/alert and add | search sourcetype=mysourcetype

0 Karma
Get Updates on the Splunk Community!

Splunk Platform | Upgrading your Splunk Deployment to Python 3.9

Splunk initially announced the removal of Python 2 during the release of Splunk Enterprise 8.0.0, aiming to ...

From Product Design to User Insights: Boosting App Developer Identity on Splunkbase

co-authored by Yiyun Zhu & Dan Hosaka Engaging with the Community at .conf24 At .conf24, we revitalized the ...

Detect and Resolve Issues in a Kubernetes Environment

We’ve gone through common problems one can encounter in a Kubernetes environment, their impacts, and the ...