newbie to splunk
Can i create an alert displaying on the splunk app,that looks like "indexing volume exceeded" alert from splunk. i am not using real-time dashboards. when i am uploading a file containing some unexpected termination , can i create an alert to the user like "Unexpected termination found in the file."
Basic Perl script like this will work or do i have to continue exploring splunk Perl script.
#!/splunk/bin/scripts
if($termination eq "UNEXPECTED") {
print "UNEXPECTED TERMINATION FOUND IN FILE!!!!!! ";
}
Hope this information explains my query.
Thank You
Bella