Splunk Search

How to edit my search to send an email if the count of a down server is greater than 0?

New Member

I'm new to Splunk and I have the Search where I check one Server for 7 Services and State=Stopped and run a stats count at the end and I'd to send out a email if the count > 0

index="*windows"  host=Q9BVPAVACT01 sourcetype=WinHostMon source=service Name=CyberTechDatabase* OR (index="*windows"  host=Q9BVPAVACT01   sourcetype=WinHostMon source=service Name="CybertechmediaManager" ) OR (index="*windows"  host=Q9BVPAVACT01 sourcetype=WinHostMon source=service Name=CybertechlicenseService   )    OR  (index="*windows"  host=Q9BVPAVACT01   sourcetype=WinHostMon source=service Name="CyberTechSystemManager" ) OR (index="*windows"  host=Q9BVPAVACT01   sourcetype=WinHostMon source=service Name="CybertechUserManager" )  OR (index="*windows"  host=Q9BVPAVACT01   sourcetype=WinHostMon source=service Name="MySQL" ) OR  (index="*windows"  host=Q9BVPAVACT01   sourcetype=WinHostMon source=service Name="CybertechRecord*" ) State=Stopped | stats  count
0 Karma

Splunk Employee
Splunk Employee

aaraneta,

So the first thing you want to do is click save as:
![alt text][1]

Then after you click this, select Alert:

[1]: /storage/temp/207661-cap1.jpgThen You will want to select the time window that you want the search to run in and the frequency, then select the add action from the triggered actions section, selecting send email:

alt text

If you have not setup your email server here is a guide to doing that.

Splunk Email setup and Configuration

0 Karma

SplunkTrust
SplunkTrust

You can greatly simplify this search too:

ex:
index=*windows host=Q9BVPAVACT01 State=Stopped source=service| stats count by Name | where count > 0

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!