Alerting

Set alert when a inline search does not return a value.

john
Communicator

HI,

I have few doubts regarding creating alert.
1.Can we create an alert only for saved searches?
2.How to send an alert if my inline search or a table in the dashboard does not return any value.
eg: iam passing a value from dropdown to all my inline searches and in one table it doesnot have any data.So i want to send an alert on that.
How it is possible.

Tags (1)
0 Karma

Drainy
Champion

The problem here is what your definition of what alerting really is.
To me alerting can only be useful if it is structured and regular, what use is there to be alerted about something... when you go look for it? Thats kind of after the fact. If you had used a scheduled search to look for this alert factor then you may have been notified an hour or two prior to you discovering it.

You could generate your own alert by writing a custom search command or running a search against an external script. Perhaps even by using outputlookup to generate values in a lookup that are checked by an external script run on a cron schedule - but it rather seems to defeat the point of alerting, surely?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...