Dashboards & Visualizations

Create a dashboard when an alert is triggered?

simomo
New Member

Use case: detect outliers 

Alert is triggered when an outlier is detected. For now I can send an email containing some information from this trigger. 

How I want to do a dashboard including the past data and detected outlier when this outlier is found.

I am not sure of the workflow. There is no option of dashboard when sending the alert through email.

 

Does it means that I have to save the alert result into an lookup file and schedule another dashboarding?

 

The dashboard itself can only be scheduled in terms of time. I can do it and then use where to find if there is an outlier. If yes, there is no way to send an alert.

 

How should I do it?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Presumably, the alert is based on the results of a search with particular time parameters. Can you reproduce the search in a dashboard with tokens for the time range. Then you can call this dashboard with the time range token values based on the alert.

0 Karma

simomo
New Member

Can you explain more detailedly about the tokens? 

Yes the alert is based on scheduled search and only alert when a condition is met (result>0). How do I automate this token and activate the dashboard?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...