Alerting

Help needed with Splunk Search

Roy_9
Motivator

Hello,

I would like to develop a Splunk alert for one of the source where we are ingesting data using REST API by configuring the scripted input on our Heavy Forwarder, I wanted to set up an email alert when ever there is an interruption in data ingestion from the source.

I am using the below search but not seeing any results.

| tstats latest(_time) as latest where index=XYZ by source
| eval recent = if(latest > relative_time(now(),"-10m"),1,0), realLatest = strftime(latest,"%c")
| where recent=0



Can someone please help me with the search?

 

Thanks

Labels (4)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Roy_9 

* Do you see any results when you search below result?

| tstats latest(_time) as latest where index=XYZ by source


* Are you running it on Search head and not on heavy forwarder?

* If it's working in normal scenario, then you can append below line and generate error.

| stats count
| appendpipe [| where count=0 | eval msg="No data found"]
| where count=0

* And you can set a schedule alert on this for example for every 1 hour and run it for the last 1 hour time. And this alert will trigger when there will be no event from the given source in last 1 hour.

 

I hope this helps!!

Roy_9
Motivator

No @Anonymous

Currently we are not getting any data for those indexes, i would like to set up an alert in such a way whenever data is being getting indexed to those indexes and during the ingestion if there are any issues.

I created a lookup with the metadata and tweaked the search a little and was able to set it up.

0 Karma

Roy_9
Motivator

hi @VatsalJagani , do you have any idea on this?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...