Splunk Search

How to do this below?

balajsoz
Path Finder

Hi all,

Am new to splunk tool and i have downloaded to use my project for reporting,analysis,charts and alerts notifications based on reports.

Currently i have created couple of dashboards and charts with timechart command for to showcase the uptime or downtime of various software applications for which the appropriate system availability data have been uploaded in to splunk as a .CSV file format.

Based on the above CSV file data, i have created the dashboards/charts.

Also am able to interlink the charts or dashboards with drilldown option xml.

Now my requests are below;
a)how can i keep my dashboards as a shortcuts or fields on home screen of splunk, so that i can directly click the same instead of navigating thru Dashboard&review menu?
b)How can i fix a alert based on a condition of data for uptime or downtime charts?for example; if am clicking the downtime or lowest value in the chart then it should send a email notification with custimised message like "X application is down and below the threshold" to respective top managers or support teams.How can i fix a alert for this?Also is that possible to generate alert automatically when a graph shows lowest downtime of certain application to concerned teams to action upon?

Please help me on my above queries which is most urgent for me.

0 Karma

emotz
Splunk Employee
Splunk Employee

Welcome to Splunk.
To customize the dashboard and keep the links you want at the top - see the docs here
http://docs.splunk.com/Documentation/Splunk/5.0.1/AdvancedDev/BuildNavigation

For alerting, you need to build the search that finds the slowness or lack of services, or state of service as stopped and then setup email notification.
Alerts typically fire from scheduled searches that run every 1 minute or 5 minutes or whatever period you want to look for the condition and then send the email.
http://docs.splunk.com/Documentation/Splunk/5.0.1/Alert/Aboutalerts

Good luck and good Splunking.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...