Alerting

Why is the alert not been triggered as expected?

POR160893
Builder

Hi,

 

I have an alert that is supposed to trigger an email each subsequent day when there are 0 logs in the last 24 hours against a particular search.

 

However, when there ARE 0 logs in the past 24 hours, my alert does not get triggered for some reason.


My alert is as follows:

POR160893_0-1673191517224.pngPOR160893_1-1673191648391.png

 




Can you please help as I do not understand why this alert is not working as expected?


Many thanks!

Labels (4)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share the search itself.

---
If this reply helps you, Karma would be appreciated.

POR160893
Builder

The search is as follows::
index="corp_security" sourcetype="dns_rpz"

The alert should send an email per day for every subsequent day when there are 0 logs in the last 24 hours

0 Karma

PickleRick
SplunkTrust
SplunkTrust
0 Karma

POR160893
Builder

So I need to add “earliest=0 latest=now | stats count” to mr current query? Would that look at just the data for the last 24 hours though?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...