Alerting

Trigger condition

kulkarnivijay27
New Member

Hi Team,

 

i have a basic search, where i need to alert when particular process name not available in raw data or last 15 minutes data. Plz suggest how to get the trigger.

 

Thanks,

Vijay K.  

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Splunk is not good to found something which is not existing 😞 Here is one blog post about it https://www.duanewaddle.com/proving-a-negative/ maybe it helps you.

Other ideas could be found from these

r. Ismo

richgalloway
SplunkTrust
SplunkTrust

If you already have the search then click the "Save as" drop-down in the top-right corner of the window and choose "Alert".  The trigger condition is set in the lower part of the subsequent form.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...