Alerting

Scheduled alert to retrieve latest event indexed every five minutes

fatjoe
Engager

I have a search query which uses dedup to get the latest event from my source type.

Search:
sourcetype = MonitorLog | dedup Username | WHERE SecondsElapsed >= 300

Username, AllocatedDirectorySize,UsedDirectorySize,PercentageUsage,LatestFileCreationTime,TimeElapsed,SecondsElapsed
amiro,300,314,105%,5/17/2017 12:01:30 PM,"0 days, 0 hours, 7 minutes, 15 seconds",435.0344144
safcom,900,907,101%,5/17/2017 11:50:18 AM,"0 days, 0 hours, 5 minutes, 6 seconds",306.0829872

How do I set up a scheduled alert which will be running this search and trigger alert when event is returned.

I have used the below but its not working.

Earliest: +0m@m
Latest: +5m@m
Cron expression: */5 * * * *

Any suggestions?

0 Karma

DalJeanis
Legend

Your query gets the latest event for each Username, only if SecondsElapsed > 300. Looks okay.

Your cron setup, however, is looking for every event from the start of this minute to the start of five minutes from now. You are looking for future events.

Try this -

Earliest: -5m@m
Latest: -0m@m
Cron expression: /5 
0 Karma

DalJeanis
Legend

Also, it would be worth leaving a couple of minutes in there for indexing to occur.

 Earliest: -7m@m
 Latest: -2m@m
 Cron expression: 2/5 * * * *  

somesoni2
Revered Legend

The full cron will be 2/5 * * * *

DalJeanis
Legend

Yeah, I got lazy...

I hate having to look up whether a particular implementation is five or six slots...

Darn Oracle with their seconds-level precision...even though things seldom run in a second...

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...