Hi,
I want to schedule one splunk alert , please let me know if below option is possible:
2nd point is basically set up splunk alert for xxx error , threshold: trigger when count>15 in last 1 hour.
1st point is for , when 1st occurrence of error came , it will not wait for count>15 and 1 hr , it will immediately trigger an email.
Please help on this.
Hi @Dharani ,
yes it's possible, you should:
If you have Enterprise Security, you don't need the summary index and you can use the Notable index.
Ciao.
Giuseppe