Dashboards & Visualizations

Create a dashboard when an alert is triggered?

simomo
New Member

Use case: detect outliers 

Alert is triggered when an outlier is detected. For now I can send an email containing some information from this trigger. 

How I want to do a dashboard including the past data and detected outlier when this outlier is found.

I am not sure of the workflow. There is no option of dashboard when sending the alert through email.

 

Does it means that I have to save the alert result into an lookup file and schedule another dashboarding?

 

The dashboard itself can only be scheduled in terms of time. I can do it and then use where to find if there is an outlier. If yes, there is no way to send an alert.

 

How should I do it?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Presumably, the alert is based on the results of a search with particular time parameters. Can you reproduce the search in a dashboard with tokens for the time range. Then you can call this dashboard with the time range token values based on the alert.

0 Karma

simomo
New Member

Can you explain more detailedly about the tokens? 

Yes the alert is based on scheduled search and only alert when a condition is met (result>0). How do I automate this token and activate the dashboard?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...