Alerting

How do I set an alert to trigger on a change in value of a count or distinct count with non-live data?

vincenthlam_tek
Engager

The Alert would not know what the value should be as it isn't statically established.

For Instance
There would be 2 hosts forwarding data (the local host and another host). I want to receive an alert when a new host is added (e.g. dc = 3)

OR, more importantly, when one stops forwarding (e.g. dc=1).

When the search runs every hour if it's been changed the trigger should activate.

Any help or insight on the matter would be greatly appreciated. Thanks

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Check out MetaWoot, this may be exactly what you're looking for

https://splunkbase.splunk.com/app/2949/

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...