Splunk Search

Search within last 5 minutes

Infinity8
New Member

Please help I am trying to make a search for a string in the past five minutes and if there are over 100 I want an email alert.

Many Thanks!

Tags (3)
0 Karma
1 Solution

Brian_Osburn
Builder

What type of information are you looking for? What does your data look like?

Searches are pretty basic - figure out what you want to look for, save it and set up an alert.

Taking a look at http://www.splunk.com/base/Documentation/latest/User/AboutSearch and http://www.splunk.com/base/Documentation/latest/User/MonitoringRecurringSituations for some more information..

View solution in original post

snowmizer
Communicator

The docs Brian reference are good places to start.

0 Karma

Brian_Osburn
Builder

What type of information are you looking for? What does your data look like?

Searches are pretty basic - figure out what you want to look for, save it and set up an alert.

Taking a look at http://www.splunk.com/base/Documentation/latest/User/AboutSearch and http://www.splunk.com/base/Documentation/latest/User/MonitoringRecurringSituations for some more information..

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...