Alerting

splunk alert every hour with all hits for the search result

arjangoos
Path Finder

we want 1 alert if something happens more than 1 time in that hour. But if it happens multiple times we want to see all those events also in the email. And we only want 1 alert in an hour.

alter type: real time
expires: 24 hours

Trigger alert when: number of results is greater than 0 in 1 hours
Trigger: Once

Trottle: yes
Supress triggering for: 1 hours

 

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

How about setting your search to run every hour looking back an hour and triggering if there are any results?

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...