Alerting

How to use Splunk to create an alert to Glip

jpage1944
New Member

The process has been to set up an alert to look back 1 minute with a snap to the start and end of the minute.
This process would not trigger on all log entries. The process was changed to a 5 minute process that would look back 5 minutes and process every log entry.

This would still not report all log entries. One minute look back schedule missed a small number of entries but with a 5 minute look back it is missing large sections of entries.
When I run the SPL query in Splunk it shows the missing log entries that should be in Glip.

How can I get Splunk to trigger an action on all log entries with no more than a 5 minute look back? [Search 5min Configuration]

(https://i.stack.imgur.com/RmEaq.png)

0 Karma

jpage1944
New Member

The receiving end was overloaded it would drop splunk webhook requests.

0 Karma

jpage1944
New Member

evzhang thanks for the edits but you have no advice on how to get a hundred % accuracy?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...