Alerting
Highlighted

How to trigger an alert to send an email only when the same hosts fails more than once ?

I have the splunk alert scheduled to run every 5 min to trigger an email to report if any splunk search peer hosts are down.

| rest splunk_server=local / services/search/distributed/peers/
| where status!="Up" AND disabled=0
| fields peerName, status | rename peerName as Instance, status as Status

I want the alert to trigger to send an email only when the same hosts fails more than once as there seems many false positive.
How to achieve this?

0 Karma
Highlighted

Re: How to trigger an alert to send an email only when the same hosts fails more than once ?

Splunk Employee
Splunk Employee
0 Karma