Splunk Enterprise

How to create a new alert under name (failed-handshake) in the custom email template?

majilan1
Path Finder

Hi Splunkers,

I spent a long time trying to figure out this story where: 

I need to create a new alert under name (failed-handshake) in the custom email template to notify tech arch teams if we receive handshake errors in the web logs.

The base search: index=X sourcetype=Y "Failed handshake due to 15 seconds timeout on channel"   I had some of these errors on 6/10, so I need to adjust the time range to build/test search and alert.

The alert should display:

1) the host 

2) the number of handshake errors
3) the time of the first instance of the error on the host

4) the time of the most recent instance of the error on the host

Is there anybody can help with  this please?

 

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...