Splunk Search

How to do this below?

balajsoz
Path Finder

Hi all,

Am new to splunk tool and i have downloaded to use my project for reporting,analysis,charts and alerts notifications based on reports.

Currently i have created couple of dashboards and charts with timechart command for to showcase the uptime or downtime of various software applications for which the appropriate system availability data have been uploaded in to splunk as a .CSV file format.

Based on the above CSV file data, i have created the dashboards/charts.

Also am able to interlink the charts or dashboards with drilldown option xml.

Now my requests are below;
a)how can i keep my dashboards as a shortcuts or fields on home screen of splunk, so that i can directly click the same instead of navigating thru Dashboard&review menu?
b)How can i fix a alert based on a condition of data for uptime or downtime charts?for example; if am clicking the downtime or lowest value in the chart then it should send a email notification with custimised message like "X application is down and below the threshold" to respective top managers or support teams.How can i fix a alert for this?Also is that possible to generate alert automatically when a graph shows lowest downtime of certain application to concerned teams to action upon?

Please help me on my above queries which is most urgent for me.

0 Karma

emotz
Splunk Employee
Splunk Employee

Welcome to Splunk.
To customize the dashboard and keep the links you want at the top - see the docs here
http://docs.splunk.com/Documentation/Splunk/5.0.1/AdvancedDev/BuildNavigation

For alerting, you need to build the search that finds the slowness or lack of services, or state of service as stopped and then setup email notification.
Alerts typically fire from scheduled searches that run every 1 minute or 5 minutes or whatever period you want to look for the condition and then send the email.
http://docs.splunk.com/Documentation/Splunk/5.0.1/Alert/Aboutalerts

Good luck and good Splunking.

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...