Alerting

when splunk error count is more than a number

rajs115
Path Finder

Hi,

   I have a log file in splunk which reports the errors when ever something failed. Now i need to run a splunk query if a same error show up in Splunk more than 3 times in last 1 hour. If it happens i need to send an alert.

Can someone suggest me the query with time in it?

 

Thanks.

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Your "specification" can be interpreted in many ways 🙂

Do you just want to search for some alert and find out if it's 3 or more events? Or maybe you can have several different kinds of alerts and want to know if any single one of them occurs more than 3 times.

 

0 Karma

rajs115
Path Finder

@PickleRick ,

 

   "Build failed" is what i need to check in each event logs over the last 1 hour. If its repeated more than 3 times(from 3 events) in last 1 hour i need to send an alert. I hope you get my question now 🙂 

 

Thanks.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Just do your search for "Build Failed" and trigger the alert when number of results is greater than 2. Easy.

0 Karma

rajs115
Path Finder

sure @PickleRick . Thank you

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...