Hi,
I have a dashboard set up which gives me hourly stats. I need to set up an alert if the value crosses 100. Is there a way to add this to the dashboard? Or should I just copy-paste the "search string" in a new alert?
Asking just to see if this can be done efficiently!
Your best bet is to just use the saved search and set up the alert that way. If you want to optimize the performance a little bit you could have the saved search do the alerting and drive the dashboard. Check this link out to get started:
http://docs.splunk.com/Documentation/Splunk/4.3.3/Developer/SavedSearchesViews
Your best bet is to just use the saved search and set up the alert that way. If you want to optimize the performance a little bit you could have the saved search do the alerting and drive the dashboard. Check this link out to get started:
http://docs.splunk.com/Documentation/Splunk/4.3.3/Developer/SavedSearchesViews
oops, meant to give this link:
http://docs.splunk.com/Documentation/Splunk/latest/Developer/DashboardIntro#How_to_build_a_dashboard