Alerting

Help with Splunk alert to identify when windows is booted to safe mode

radparik
Engager

Hello,

I am trying to monitor if a machine was booted to safe mode. Essentially, if there are more than 5 services dependency failures from a single IP address - the alert should trigger. 

Does anyone know how I can go about this?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

This question is answered at https://community.splunk.com/t5/Alerting/Setting-up-an-Alert-for-Computer-Booting-in-Safe-Mode/m-p/3...

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...