Splunk Cloud Platform

Create an alert that monitors the lost of intake by indexes

fekev85566
New Member

Good afternoon,

I want to generate an alert to control the loss of ingestion of the events in the different indexes, but I want to do it that for according to the index that is, the time of ingestion varies.
That is to say, the windows servers, ingest me almost every minute, on the other hand the antivirus only ingests if it detects something, which can be that it generates at least one event every 5 days. So it does not make sense to check every minute, because the antivirus would generate a lot of noise, and not every 2 days, because in the case of losing communication with the forwarder I would realize 2 days later, and the service would not work efficiently.
Does anyone know if it is possible to generate this alert, without having to generate an alert by index?

Thank you very much in advance!

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

How does Splunk know how long an interval between events being ingested is deemed intolerable for each index?

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...