Alerting

Alerting
Community Activity
RecoMark0
Hello, I'd like to combine the following two searches, to a single alert. The alert would send an email to a specifi...
by RecoMark0 Path Finder in Alerting 09-18-2014
0 6
0
6
PVBsupport
I am running Splunk 6.1.3 and while in Search, in the New Search area, I have entered "EventCode=1001". A few entrie...
by PVBsupport New Member in Alerting 09-18-2014
0 3
0
3
nterry
So I have a search that counts the number of successful dns server health checks over the last 5 minutes for all of o...
by nterry Path Finder in Alerting 09-17-2014
0 7
0
7
echalex
Hi, I have problems understanding a situation. First, the problem manifested itself when a colleague approached me wi...
by echalex Builder in Alerting 09-17-2014
1 8
1
8
kavraja
I got a message today saying "You are low in disk space on partition "D:\splunk\sep\db". Indexing has been paused. ...
by kavraja Path Finder in Alerting 09-16-2014
0 8
0
8
splunkn
I am in need of the following requirement. Could anyone help me with the possible ideas? I need to create an alert i...
by splunkn Communicator in Alerting 09-12-2014
0 1
0
1
Michael
Sharing a lesson learned... Splunk 6.1.3 (but I think would apply to most) on RHEL 6. I came in one morning to being...
by Michael Contributor in Alerting 09-11-2014
2 4
2
4
lagnone_splunk
Looking for assistance in crafting a scheduled search that sends a notification when I see a specific syslog message ...
by lagnone_splunk Splunk Employee Splunk Employee in Alerting 09-08-2014
0 1
0
1
ljbur1
Does anyone know if it is possible, and if so, what the syntax is for passing a literal argument to an alert script. ...
by ljbur1 New Member in Alerting 09-03-2014
0 2
0
2
hexx
Right after upgrading to 6.1, I noticed that some scheduled real-time searches fail to send emails or trigger any oth...
by hexx Splunk Employee Splunk Employee in Alerting 09-02-2014
4 2
4
2
the_wolverine
I'm trying to set up Splunk to detect anomalies. An example would be searching on DHCP logs for a new MAC Address. ...
by the_wolverine Champion in Alerting 09-02-2014
0 3
0
3
Bliide
I have an alert that is triggering when conditions are not met. The search for the alert is: index=foo earliest=-1d...
by Bliide Path Finder in Alerting 09-02-2014
0 1
0
1
AlexMcDuffMille
Hello, I am currently able to successfully have a script execute after a search when located in $SPLUNK_HOME/bin/scr...
by AlexMcDuffMille Communicator in Alerting 08-27-2014
0 6
0
6
sbsbb
I've made a scripted alert in python, and put it in py app directory .../splunk/etc/apps/myapp/bin/scripts/scripted_a...
by sbsbb Builder in Alerting 08-22-2014
0 2
0
2
allladin101
Hi All, I want to check if there is a way by which, I could set up an alert when the error count of the latest week ...
by allladin101 Explorer in Alerting 08-21-2014
0 4
0
4
ashari
I want to run a search in splunk to find out that all the devices attached to the splunk server are generating logs. ...
by ashari Explorer in Alerting 08-19-2014
2 5
2
5
gajananh999
Dear All, I am working with making a Splunk alert. I have two folders, one is IN and OUT. One process is putting fil...
by gajananh999 Contributor in Alerting 08-18-2014
0 1
0
1
hjwang
As i know, splunk use the length of fields from shortest to longest by default, how to define the order in search com...
by hjwang Contributor in Alerting 08-13-2014
0 2
0
2
aniketb
Hi, I have an alert that calls a script when invoked. The result have the 1st column as ip address [host]. I want t...
by aniketb Path Finder in Alerting 08-07-2014
1 1
1
1
raindrop18
I have put this string on my search and set to run every 15 min, the objective is to send me no log activity on Splun...
by raindrop18 Communicator in Alerting 08-06-2014
0 7
0
7
netwrkr
We are using a Perl script to create tickets when a given event meets a certain threshold. How can we include the re...
by netwrkr Communicator in Alerting 08-04-2014
2 9
2
9
stwong
Hi, I'm trying to monitor new syslog events and send email when seeing new log entries. I tried to schedule search li...
by stwong Communicator in Alerting 08-03-2014
0 3
0
3
martin_mueller
I've successfully installed the Splunk Mobile Access Server in a local network, and can use an iPhone to access dashb...
by SplunkTrust SplunkTrust in Alerting 07-30-2014
1 2
1
2
koshyk
We got a scenario whereby there are multiple search heads. (Say 2x of them). The main reason being load balancing (bo...
by koshyk Super Champion in Alerting 07-28-2014
1 7
1
7
echalex
Hi, I'm seeing a weird issue. We have a setup of three search head pools. One user has a real-time search creating a...
by echalex Builder in Alerting 07-27-2014
0 2
0
2