Alerting

Indexes Alert If No Incoming Data

jmc94
Loves-to-Learn

Would anyone have an up to date way of looking at all indexes and if an index has not received any data in 60 minutes or so alert? I have seen several ways of looking at this by host but would prefer to look at it from the index level.

 

Thanks!! 

Labels (2)
0 Karma

burwell
SplunkTrust
SplunkTrust
|  tstats count WHERE index=myindexname earliest=-60m latest=now
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...