Alerting

alert

Param1987
Engager

Hi 

Currently, My scheduled alert runs every five minutes but I need to get it triggered when the event count goes more than 2 in a minute. What is the best way to handle it? 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

basically you should/could combine those event with bin or eventstats, based on your requirements (fixed or sliding span). 

Here is one old answer for this https://community.splunk.com/t5/Alerting/how-to-generate-alert-based-on-the-count-of-unique-filed-va... and you could found more quite easily.

r. Ismo

Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...