Splunk Search

How to get an alert if the specific search takes more than 10 min?

prerana_jain
Explorer

Ex: "Acquired" is a keyword.
This keyword is getting for every minute.
I have to get alert if this keyword is not getting generated for more than 10 min.

0 Karma

woodcock
Esteemed Legend

Your phrasing is unclear. Add a comment and explain it with many more words/sentences.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Run the following search every 5-10 minutes. Set it to trigger an alert if the result count is equal to zero.

index=foo "Acquired" earliest=-10m@m
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...