Alerting

Best way to baseline for alerting

aohls
Contributor

General question on how people might be baselining for alerts. At this time our alerting is over complicated and cumbersome, our basic alert setup is 150+ lines. I have looked at cutting this down a lot by using some prediction models which seems pretty good but wondering if there are any good articles or documents others have come across on this.

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Splunk Certification Support Alert | Pearson VUE Outage

Splunk Certification holders and candidates!  Please be advised of an upcoming system maintenance period for ...

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...