Splunk Search

Splunk Alert

whitecat001
Explorer

Am having issue with a Splunk alert triggering for daily snapshot of aws account ids. The alert is suppose to trigger when the account ids are less than 50 and missing some of the aws accounts. Is there a way to troubleshoot this issue to make sure all the account ids are complete to avoid the alert triggering 

Labels (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@whitecat001 Confirm the SPL used in the alert.

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, there is a way to troubleshoot.  Run the alert query manually and modify it until the expected results are produced.

If you want help with this, please share the alert SPL.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...