Getting Data In

Sourcetype not reporting in Splunk query

anandhalagaras1
Contributor

Hi Team,

We have a requirement that is I have few of the sourcetypes configured from our end which contains very important logs. So if there are no logs from those particular sourcetypes then we need to get an alert for the same. So how should we need to configure the alert.

Hence kindly guide me with the search query for the same. i.e. The condition is that the search query would be running for every 15 minutes and it should trigger an alert if any of these sourcetypes are not sending logs to splunk for every 15 minutes.

Example:

index= windows sourcetype=dns

index=firewall sourcetype=syslog

index=os sourcetype=top etc.

So kindly help me with the query.

 

 

Labels (2)
0 Karma

rnowitzki
Builder

Hi @anandhalagaras1 

You already have what you need basically.

Go to settings -> Sarch, Reports and Alerts, click "new Alert" in top right.

As search you would put in for example index=windows sourcetype=dns
Make sure Alert Type is set to "Scheduled" and select "Run on Cron Schedule
Use this Cron Expression  */15 * * * *  (run every 15th minute).
As Time Range select "Last 15 Minutes".
As Trigger Condition set: "Number of Results" and "is equal to " 0.

At the bottom you can configure the kind of alert action you need (email, webhook posting, call the police...)

Hope this helps.
BR
Ralph

Edit:  Instead of returning all the Events, it would be better (from a performance/ressource usage pov) to run a stats command like:

index=windows sourcetype=dns | stats count

And  alert based on the count field.
So, once you have the alerting running, this would be a good point to optimize it.

--
Karma and/or Solution tagging appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...