Splunk Search

How to get an alert if the specific search takes more than 10 min?

Explorer

Ex: "Acquired" is a keyword.
This keyword is getting for every minute.
I have to get alert if this keyword is not getting generated for more than 10 min.

0 Karma

Esteemed Legend

Your phrasing is unclear. Add a comment and explain it with many more words/sentences.

0 Karma

SplunkTrust
SplunkTrust

Run the following search every 5-10 minutes. Set it to trigger an alert if the result count is equal to zero.

index=foo "Acquired" earliest=-10m@m
---
If this reply helps you, an upvote would be appreciated.
0 Karma