AppD Archive

New BTs compared againsts a baseline value of 0

CommunityUser
Splunk Employee
Splunk Employee

I have configured some OOTB health rules and a policy to send out an email alert on those. The default daily baseline, as I understand it, looks at the hour-by-hour value of data over the last 7 days to compare. I have new BTs being detected, and alert emails are being sent because this baseline has not been build yet. Is there any option when creating this to exclude BTs which do not have a baseline built yet?

I have attached a screenshot of the alert confition in the email being sent. Obviously, this is a useless alert, and I would like to be able to continue to use the baseline for those BTs that have been reported for a while, but not alert when new BTs are detected.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...