Alerting

Splunk alert to verify results sent in previous alert

bsaujla131984
Path Finder

I have an alert which checks the number of messages stuck in the queue with suppressing of 4 hours otherwise there will be number of alerts.

Now I need to make it more dynamic means it should alert only if alert has not been sent for same result in last 4 hours.

Can someone guide with this please?

Labels (1)
0 Karma
1 Solution

DalJeanis
SplunkTrust
SplunkTrust

There is an option to suppress per result rather than for the entire search.

You must write the search so that it gets one line of output per item at the level you want to suppress.

If you give more specific information about your needs, then we can give a more specific reply.

View solution in original post

0 Karma

DalJeanis
SplunkTrust
SplunkTrust

There is an option to suppress per result rather than for the entire search.

You must write the search so that it gets one line of output per item at the level you want to suppress.

If you give more specific information about your needs, then we can give a more specific reply.

View solution in original post

0 Karma

bsaujla131984
Path Finder

Can you let me know how can suppress the result rather than whole search?

0 Karma

bsaujla131984
Path Finder

Thanks DalJeanis. It worked.

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!