Splunk Search

How to create trigger alert if the count in the dashboard is zero?

prettysunshinez
Explorer

I would want an alert to be triggered and sent to mail if a particular panel has the count=0 in the dashboard

how should we achieve that

pls help

Tags (3)
0 Karma

prettysunshinez
Explorer

@gcusello  The search of the panel has values parsed from the other panels in the dashbaord.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Anyway, the only solution is the one I described:

you have to create one single search and save it as an alert, it isn't possible to create an alert taking parameters from other panels or inputs.

I could add that the concept of alert is to have a rule that automatically checks the conditions and triggers without human intervenes.

You could also add the sendmail command to a panel, but in this way, the mail is sent every time you open the dashboard and I don't think that's acceptable.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @prettysunshinez,

you have only to take the search in the panel and run it in the Search dashboard, then you have to save it as an Alert, adding the other informations: trigger condition (count=0), scheduling, time frame, etc...).

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Manual Instrumentation with Splunk Observability Cloud: The What and Why

If you've ever worked with distributed systems, you’ve likely felt the pain of a frontend throwing errors, ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and Splunk ES Protecting a ...

It's Customer Success Time at .conf25

Hello Splunkers,   Ready for .conf25? The customer success and experience team is and can’t wait to see you ...