Alerting

Why is the alert not been triggered as expected?

POR160893
Builder

Hi,

 

I have an alert that is supposed to trigger an email each subsequent day when there are 0 logs in the last 24 hours against a particular search.

 

However, when there ARE 0 logs in the past 24 hours, my alert does not get triggered for some reason.


My alert is as follows:

POR160893_0-1673191517224.pngPOR160893_1-1673191648391.png

 




Can you please help as I do not understand why this alert is not working as expected?


Many thanks!

Labels (4)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share the search itself.

---
If this reply helps you, Karma would be appreciated.

POR160893
Builder

The search is as follows::
index="corp_security" sourcetype="dns_rpz"

The alert should send an email per day for every subsequent day when there are 0 logs in the last 24 hours

0 Karma

PickleRick
SplunkTrust
SplunkTrust
0 Karma

POR160893
Builder

So I need to add “earliest=0 latest=now | stats count” to mr current query? Would that look at just the data for the last 24 hours though?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...