Dashboards & Visualizations

Create a dashboard when an alert is triggered?

simomo
New Member

Use case: detect outliers 

Alert is triggered when an outlier is detected. For now I can send an email containing some information from this trigger. 

How I want to do a dashboard including the past data and detected outlier when this outlier is found.

I am not sure of the workflow. There is no option of dashboard when sending the alert through email.

 

Does it means that I have to save the alert result into an lookup file and schedule another dashboarding?

 

The dashboard itself can only be scheduled in terms of time. I can do it and then use where to find if there is an outlier. If yes, there is no way to send an alert.

 

How should I do it?

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Presumably, the alert is based on the results of a search with particular time parameters. Can you reproduce the search in a dashboard with tokens for the time range. Then you can call this dashboard with the time range token values based on the alert.

0 Karma

simomo
New Member

Can you explain more detailedly about the tokens? 

Yes the alert is based on scheduled search and only alert when a condition is met (result>0). How do I automate this token and activate the dashboard?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...