I am trying to create a splunk alert, which sends an email if a key value is missing.
host="myhost" sourcetype="access_log" "Key_Word in the access logs'"
Usually i get the log entries every 30 mins, i want to get alerted via an email if "Key_Word in the access logs" is missing from the access logs, can someone guide me on this?
Hi @praneethlekkala,
it's easy:
Ciao.
Giuseppe
Thanks!! let me try this..
Hi @praneethlekkala,
good for you!
Ciao and happy splunking.
Giuseppe
P.S.: Karma Points are appreciated by all the contributors 😉
Thanks
Hi @praneethlekkala,
it's easy:
Ciao.
Giuseppe