Alerting

splunk alert for no user activities + no alert if splunk is not getting populate

gnshah12345
Observer

I already have an alert setup if a user does not have activity. The alert is set with number of results = 0. However, we have situation when splunk forwarder did not send data because the underlying logs stopped populating. This created a false negative that user is not logging. How do I incorporate the scenario that if no logs are coming than no alert.
The current search as follows.
index=appl_index user="xyz"
I would check
index=appl_index | stats count | if (count=0,do not alert, else go with my current query)

Thanks in advance.

Tags (1)
0 Karma

renjith_nair
Legend

@gnshah12345,

Try this. You may adjust the last condition according to your requirement.

index=appl_index |stats count(eval(user="xyz")) as userCount,count as total|where userCount>0 OR total < 1
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...