- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ryhluc01
Communicator
12-19-2018
01:57 PM
Hi all,
I need to set up an alert condition to notify me if the report doesn't generate data for more than 5 minute's
stats max(_time) as "Last Report Run" by reltime|dedup "Last Report Run" |convert timeformat=%l:%M%p ctime("Last Report Run")|rename reltime as "Time Since Last Report"|sort -"Time Since Last Report"
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ryhluc01
Communicator
12-26-2018
08:31 AM
Answering my own question: This result can be achieved by specifying the number or results as the trigger condition.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ryhluc01
Communicator
12-26-2018
08:31 AM
Answering my own question: This result can be achieved by specifying the number or results as the trigger condition.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
12-26-2018
10:51 AM
@ryhluc01 If your problem is resolved, please accept the answer to help future readers.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
