Alerting

How to query for alert if the device is down and no up stage log is received in 15 minutes?

Mohanveera1
Explorer

Hello Splunkers,

I am trying to create an alert when the log with "UP" state is not received within 15 minutes from the time of "DOWN" state log received. So can anyone help me out...

Scenario:

When the device is Down the splunk will receive the log from solar-winds that the device is "DOWN" along with the host name in the log. So if the splunk doesn't receive the log that containing the "UP" state from the solar-winds in the next 15 minutes then an alert must be raised.

So can anyone help me to create an Query for the alert for the above scenario.

Thanks in Advance....

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Mohanveera1 ,

please see my approach and adapt it to your real search:

index=your_index (status="UP" OT status="DOWN") earliest=-30m@m latest=@m
| transaction host startswith=UP endswith=DOWN
| where duration>900

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Mohanveera1 ,

please see my approach and adapt it to your real search:

index=your_index (status="UP" OT status="DOWN") earliest=-30m@m latest=@m
| transaction host startswith=UP endswith=DOWN
| where duration>900

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...