I have a requirement to write a search query when the REST API got down and need to send an email alert for the same. Can anyone help me to do the search query as i am new to splunk.
Do you have the events of "down" in splunk or do you need to explicitly call the rest endpoint to see if it works?
Hi renjith, need to explicitly call the rest endpoint to see if it works?
You could use https://splunkbase.splunk.com/app/1546/ and forward the result to Splunk. Once this is done, you could search the splunk events, you could look for unexpected errors and alert