Splunk Search

How to create trigger alert if the count in the dashboard is zero?

prettysunshinez
Explorer

I would want an alert to be triggered and sent to mail if a particular panel has the count=0 in the dashboard

how should we achieve that

pls help

Tags (3)
0 Karma

prettysunshinez
Explorer

@gcusello  The search of the panel has values parsed from the other panels in the dashbaord.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Anyway, the only solution is the one I described:

you have to create one single search and save it as an alert, it isn't possible to create an alert taking parameters from other panels or inputs.

I could add that the concept of alert is to have a rule that automatically checks the conditions and triggers without human intervenes.

You could also add the sendmail command to a panel, but in this way, the mail is sent every time you open the dashboard and I don't think that's acceptable.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @prettysunshinez,

you have only to take the search in the panel and run it in the Search dashboard, then you have to save it as an Alert, adding the other informations: trigger condition (count=0), scheduling, time frame, etc...).

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...