Alerting

How to use Splunk to create an alert to Glip

jpage1944
New Member

The process has been to set up an alert to look back 1 minute with a snap to the start and end of the minute.
This process would not trigger on all log entries. The process was changed to a 5 minute process that would look back 5 minutes and process every log entry.

This would still not report all log entries. One minute look back schedule missed a small number of entries but with a 5 minute look back it is missing large sections of entries.
When I run the SPL query in Splunk it shows the missing log entries that should be in Glip.

How can I get Splunk to trigger an action on all log entries with no more than a 5 minute look back? [Search 5min Configuration]

(https://i.stack.imgur.com/RmEaq.png)

0 Karma

jpage1944
New Member

The receiving end was overloaded it would drop splunk webhook requests.

0 Karma

jpage1944
New Member

evzhang thanks for the edits but you have no advice on how to get a hundred % accuracy?

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...