Hi everyone. I have the following issue using Splunk Enterprise (v. 9.2.0).
I developed a script to send a CSV dataset to Splunk using a data input (I know it's possible to upload CSV directly, but I have specific requirements). Then, I defined a Real-Time alert having the following settings:
That is, "trigger an alert everytime, during a minute, the provided query returns at least 1 result" (in the actual situation the threshold will be 600 and not 1, but this is a test).
When I enable the alert and start sending data, I see this window upadting in real time:
But no alert is triggered, why?
Hi @Guido2000,
at first, please, next time add also your search in text mode otherwise is more difficoult to answer you.
Anyway, let me understand: do you want to trigger an alert when yu have more than 600 results avery minute, is it true?
In these cases I prefer to have the threshold inside the search (more a greater readability):
index="fabrication-gear-index" sourcetype="Vehicle-logs" source="ud06148" CAN_ID="44c"
| timechart span=1m count
| where count>600then don't use the minus char (-) in the index or sourcetype name because Splunk identifies this chare as the minus, use underscore (_) and you need to use quotes.
Ciao.
Giuseppe