Monitoring Splunk

Splunk alert for multiple time?

karthi2809
Builder

Thanks in advance.

We have scenario that we need to send alerts multiple times .

 

1. Lagging      E.g  Lets put Threshold time : 1 Hour  
20/02 10:00 AM NZT : Lagging encountered after 1 Hour threshold -> Alert#1 via email with subject : Total lag time     
20/02 11:00 AM NZT : Lagging still occur -> Alert#2 via email with subject : Total lag time   2 hour (Accumulated lagging hour) + Create Incidents in ServiceNow
      20/02 13:00 PM NZT : Lagging encountered after 1 Hour threshold -> Alert#3 via email with subject : Total lag time     
20/02 14:00 PM NZT : Lagging encountered after 1 Hour threshold -> Alert#4 via email with subject : Total lag time ---Got fixed

 

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...