Alerting

Trigger an email alert when status code is other than 200

Bala
Explorer

Hi Team,

i want to configure an mail alert when the status code is 400,401, 500... which means other than 200 trigger the alert. check every 30 min once.

Bala_0-1642672563175.png

 

Labels (1)
Tags (1)
0 Karma

sajohnson6
Explorer

I agree with Skrajkumar, the only other suggestions I would offer is if you are looking for an http status code, I would do status!=2*, that way it ignores all 2xx HTTP responses.

0 Karma

skrajkumar_splu
Splunk Employee
Splunk Employee

Try scheduling an alert with condition "|search status !=200" with a cron schedule of  "*/30 * * * *".

Settings->Searches, Reports, and Alerts ->new alert

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...