Alerting

alert

Param1987
Engager

Hi 

Currently, My scheduled alert runs every five minutes but I need to get it triggered when the event count goes more than 2 in a minute. What is the best way to handle it? 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

basically you should/could combine those event with bin or eventstats, based on your requirements (fixed or sliding span). 

Here is one old answer for this https://community.splunk.com/t5/Alerting/how-to-generate-alert-based-on-the-count-of-unique-filed-va... and you could found more quite easily.

r. Ismo

Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...