Alerting

Set alert when a inline search does not return a value.

john
Communicator

HI,

I have few doubts regarding creating alert.
1.Can we create an alert only for saved searches?
2.How to send an alert if my inline search or a table in the dashboard does not return any value.
eg: iam passing a value from dropdown to all my inline searches and in one table it doesnot have any data.So i want to send an alert on that.
How it is possible.

Tags (1)
0 Karma

Drainy
Champion

The problem here is what your definition of what alerting really is.
To me alerting can only be useful if it is structured and regular, what use is there to be alerted about something... when you go look for it? Thats kind of after the fact. If you had used a scheduled search to look for this alert factor then you may have been notified an hour or two prior to you discovering it.

You could generate your own alert by writing a custom search command or running a search against an external script. Perhaps even by using outputlookup to generate values in a lookup that are checked by an external script run on a cron schedule - but it rather seems to defeat the point of alerting, surely?

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...