Splunk Search

Fire Alert Based on Stats

trever
Loves-to-Learn

I have a stats query that I would like to fire only when a new value for a field comes in. I have my alert set up like this:

alt text

I can run the search in the alert and I see values, but the alert does not fire, what do I have set up wrong?

0 Karma

jadengoho
Builder

is your Email server setup ?
Settings > Server Settings > Email Settings?

Also can all actions on the alert to monitor if it triggers on the Activity > Triggered activity

0 Karma

trever
Loves-to-Learn

Yes my email server is set up.

It says "There are no fired events for this alert"

0 Karma

trever
Loves-to-Learn

Activity > Triggered Alerts shows "No triggered alerts found"

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...