Is there an easy way to implement a recovery alert in the same query as the alert query?
For example if I have a system that creates a log file every 10 min if everything is working. I built a query that runs every half an hour and tells me if there is something new in the log location. That part is easy enough but I would also like the same query to be able to send a recovery notification.
Or is this not going to be possible because I want to trigger two different actions because from what I can tell you can only configure the one email or slack action per alert?
I did see that there is a splunk addon with VictorOps that has this functionality but I wanted to check here first before I went down that route.
... View more
Hey guys I'm trying to create a dashboard that shows any host with a group of specified hosts that are not returning data from a specific source type So what I have been trying so far to no success is Index=xyz Host=abc Sourcetype=def | timechart span=30min count by host Where count < 1 usenull=f useother=f This won't show anything because it going to have no events to report but I'm not sure how I can create a variable base upon have no results back within a specific time then do a timechart base upon the new variable by host Unless I'm going about this completely wrong lol please help
... View more