Alerting

Trigger condition

kulkarnivijay27
New Member

Hi Team,

 

i have a basic search, where i need to alert when particular process name not available in raw data or last 15 minutes data. Plz suggest how to get the trigger.

 

Thanks,

Vijay K.  

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Splunk is not good to found something which is not existing 😞 Here is one blog post about it https://www.duanewaddle.com/proving-a-negative/ maybe it helps you.

Other ideas could be found from these

r. Ismo

richgalloway
SplunkTrust
SplunkTrust

If you already have the search then click the "Save as" drop-down in the top-right corner of the window and choose "Alert".  The trigger condition is set in the lower part of the subsequent form.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...