Alerting

How to write a Splunk alert query to trigger alert when there are no transactions?

aaa2324
Explorer

I want to create Splunk alert when there are no transactions continuously for 30mins. Kindly assist.

Labels (1)

mehmetgunertr
Explorer
index="abc" (EVENT=1 OR EVENT=2)| transaction MACHINE startswith=(EVENT=1) endswith=(EVENT=2)|where duration> 1800 | table  duration  EVENT MACHINE NAME DESCR
0 Karma

aaa2324
Explorer

Can you please explain how the below query works , what is event=1 and 2 and what is machine ?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Create a report that counts the transactions in the previous 30 minutes and trigger the alarm when the count is zero

Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...