Alerting

search within last 5 minutes

ssehgal
Explorer

hello,
i want to trigger an alert on splunk where if i dont have any data coming in within 5 minutes splunk sends out an alert.

I am using time as -5m@m and @m

thanks

Tags (2)
0 Karma
1 Solution

lukejadamec
Super Champion

Not sure which part you need help with....

Create your search WithOut a start and stop time.

Save the search.

Go to Manager>Searches and Reports>

In the Time Range

Start -5m@s Finish Time now

Find the search you saved, open it, and select Schedule this Search

For Schedule Type, select cron, and enter */5 * * * *

For Alert Condition select If Number Of Events, and the condition Is Less Than 1

For Alert Actions select Send Email Enable. Enter a subject and your email address.

View solution in original post

0 Karma

lukejadamec
Super Champion

Not sure which part you need help with....

Create your search WithOut a start and stop time.

Save the search.

Go to Manager>Searches and Reports>

In the Time Range

Start -5m@s Finish Time now

Find the search you saved, open it, and select Schedule this Search

For Schedule Type, select cron, and enter */5 * * * *

For Alert Condition select If Number Of Events, and the condition Is Less Than 1

For Alert Actions select Send Email Enable. Enter a subject and your email address.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...