Alerting

Set alert when a inline search does not return a value.

john
Communicator

HI,

I have few doubts regarding creating alert.
1.Can we create an alert only for saved searches?
2.How to send an alert if my inline search or a table in the dashboard does not return any value.
eg: iam passing a value from dropdown to all my inline searches and in one table it doesnot have any data.So i want to send an alert on that.
How it is possible.

Tags (1)
0 Karma

Drainy
Champion

The problem here is what your definition of what alerting really is.
To me alerting can only be useful if it is structured and regular, what use is there to be alerted about something... when you go look for it? Thats kind of after the fact. If you had used a scheduled search to look for this alert factor then you may have been notified an hour or two prior to you discovering it.

You could generate your own alert by writing a custom search command or running a search against an external script. Perhaps even by using outputlookup to generate values in a lookup that are checked by an external script run on a cron schedule - but it rather seems to defeat the point of alerting, surely?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...