Hi, I am looking for an email in KPI ad-hoc search which is supposed to arrive at -7-15am. if it doesn't arrive at 07:15 i want KPI threshold to go amber and if i don't receive it till 07:45(30 mins later) I want my threshold value to turn red. Only when the email arrives values changes to green.
Any help appreciated. Thanks
you can configure time based KPI thresholds along with base/adhoc search. Please refer this page
https://docs.splunk.com/Documentation/ITSI/4.5.0/SI/TimePolicies