Splunk Search

How to do this below?

balajsoz
Path Finder

Hi all,

Am new to splunk tool and i have downloaded to use my project for reporting,analysis,charts and alerts notifications based on reports.

Currently i have created couple of dashboards and charts with timechart command for to showcase the uptime or downtime of various software applications for which the appropriate system availability data have been uploaded in to splunk as a .CSV file format.

Based on the above CSV file data, i have created the dashboards/charts.

Also am able to interlink the charts or dashboards with drilldown option xml.

Now my requests are below;
a)how can i keep my dashboards as a shortcuts or fields on home screen of splunk, so that i can directly click the same instead of navigating thru Dashboard&review menu?
b)How can i fix a alert based on a condition of data for uptime or downtime charts?for example; if am clicking the downtime or lowest value in the chart then it should send a email notification with custimised message like "X application is down and below the threshold" to respective top managers or support teams.How can i fix a alert for this?Also is that possible to generate alert automatically when a graph shows lowest downtime of certain application to concerned teams to action upon?

Please help me on my above queries which is most urgent for me.

0 Karma

emotz
Splunk Employee
Splunk Employee

Welcome to Splunk.
To customize the dashboard and keep the links you want at the top - see the docs here
http://docs.splunk.com/Documentation/Splunk/5.0.1/AdvancedDev/BuildNavigation

For alerting, you need to build the search that finds the slowness or lack of services, or state of service as stopped and then setup email notification.
Alerts typically fire from scheduled searches that run every 1 minute or 5 minutes or whatever period you want to look for the condition and then send the email.
http://docs.splunk.com/Documentation/Splunk/5.0.1/Alert/Aboutalerts

Good luck and good Splunking.

Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...