Hello,
I am trying to monitor if a machine was booted to safe mode. Essentially, if there are more than 5 services dependency failures from a single IP address - the alert should trigger.
Does anyone know how I can go about this?
This question is answered at https://community.splunk.com/t5/Alerting/Setting-up-an-Alert-for-Computer-Booting-in-Safe-Mode/m-p/3...