Alerting

How to use Splunk to create an alert to Glip

jpage1944
New Member

The process has been to set up an alert to look back 1 minute with a snap to the start and end of the minute.
This process would not trigger on all log entries. The process was changed to a 5 minute process that would look back 5 minutes and process every log entry.

This would still not report all log entries. One minute look back schedule missed a small number of entries but with a 5 minute look back it is missing large sections of entries.
When I run the SPL query in Splunk it shows the missing log entries that should be in Glip.

How can I get Splunk to trigger an action on all log entries with no more than a 5 minute look back? [Search 5min Configuration]

(https://i.stack.imgur.com/RmEaq.png)

0 Karma

jpage1944
New Member

The receiving end was overloaded it would drop splunk webhook requests.

0 Karma

jpage1944
New Member

evzhang thanks for the edits but you have no advice on how to get a hundred % accuracy?

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...