AppD Archive

New BTs compared againsts a baseline value of 0

CommunityUser
Splunk Employee
Splunk Employee

I have configured some OOTB health rules and a policy to send out an email alert on those. The default daily baseline, as I understand it, looks at the hour-by-hour value of data over the last 7 days to compare. I have new BTs being detected, and alert emails are being sent because this baseline has not been build yet. Is there any option when creating this to exclude BTs which do not have a baseline built yet?

I have attached a screenshot of the alert confition in the email being sent. Obviously, this is a useless alert, and I would like to be able to continue to use the baseline for those BTs that have been reported for a while, but not alert when new BTs are detected.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...