Alerting

Set alert when a inline search does not return a value.

john
Communicator

HI,

I have few doubts regarding creating alert.
1.Can we create an alert only for saved searches?
2.How to send an alert if my inline search or a table in the dashboard does not return any value.
eg: iam passing a value from dropdown to all my inline searches and in one table it doesnot have any data.So i want to send an alert on that.
How it is possible.

Tags (1)
0 Karma

Drainy
Champion

The problem here is what your definition of what alerting really is.
To me alerting can only be useful if it is structured and regular, what use is there to be alerted about something... when you go look for it? Thats kind of after the fact. If you had used a scheduled search to look for this alert factor then you may have been notified an hour or two prior to you discovering it.

You could generate your own alert by writing a custom search command or running a search against an external script. Perhaps even by using outputlookup to generate values in a lookup that are checked by an external script run on a cron schedule - but it rather seems to defeat the point of alerting, surely?

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...