Alerting

Indexes Alert If No Incoming Data

jmc94
Loves-to-Learn

Would anyone have an up to date way of looking at all indexes and if an index has not received any data in 60 minutes or so alert? I have seen several ways of looking at this by host but would prefer to look at it from the index level.

 

Thanks!! 

Labels (2)
0 Karma

burwell
SplunkTrust
SplunkTrust
|  tstats count WHERE index=myindexname earliest=-60m latest=now
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...