Alerting

How do I trigger an alert if no event is received after a certain time?

Engager

Our splunk instance is receiving events / log information via UDP. Is it possible to trigger an email alert if I have not received events after a certain period of time?

0 Karma
1 Solution

SplunkTrust
SplunkTrust

pasting to an answer
hello,
how about something like that:

 <your search for events for this data> earliest= latest=now | stats count 

save the alert and trigger if count = 0

View solution in original post

SplunkTrust
SplunkTrust

pasting to an answer
hello,
how about something like that:

 <your search for events for this data> earliest= latest=now | stats count 

save the alert and trigger if count = 0

View solution in original post

SplunkTrust
SplunkTrust

hello,
how about something like that:

<your search for events for this data> earliest= latest=now | stats count 

save the alert and trigger if count = 0

Engager

this worked thank you

0 Karma