Splunk Search

Search within last 5 minutes

Infinity8
New Member

Please help I am trying to make a search for a string in the past five minutes and if there are over 100 I want an email alert.

Many Thanks!

Tags (3)
0 Karma
1 Solution

Brian_Osburn
Builder

What type of information are you looking for? What does your data look like?

Searches are pretty basic - figure out what you want to look for, save it and set up an alert.

Taking a look at http://www.splunk.com/base/Documentation/latest/User/AboutSearch and http://www.splunk.com/base/Documentation/latest/User/MonitoringRecurringSituations for some more information..

View solution in original post

snowmizer
Communicator

The docs Brian reference are good places to start.

0 Karma

Brian_Osburn
Builder

What type of information are you looking for? What does your data look like?

Searches are pretty basic - figure out what you want to look for, save it and set up an alert.

Taking a look at http://www.splunk.com/base/Documentation/latest/User/AboutSearch and http://www.splunk.com/base/Documentation/latest/User/MonitoringRecurringSituations for some more information..

Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...