Splunk Search

Search within last 5 minutes

Infinity8
New Member

Please help I am trying to make a search for a string in the past five minutes and if there are over 100 I want an email alert.

Many Thanks!

Tags (3)
0 Karma
1 Solution

Brian_Osburn
Builder

What type of information are you looking for? What does your data look like?

Searches are pretty basic - figure out what you want to look for, save it and set up an alert.

Taking a look at http://www.splunk.com/base/Documentation/latest/User/AboutSearch and http://www.splunk.com/base/Documentation/latest/User/MonitoringRecurringSituations for some more information..

View solution in original post

snowmizer
Communicator

The docs Brian reference are good places to start.

0 Karma

Brian_Osburn
Builder

What type of information are you looking for? What does your data look like?

Searches are pretty basic - figure out what you want to look for, save it and set up an alert.

Taking a look at http://www.splunk.com/base/Documentation/latest/User/AboutSearch and http://www.splunk.com/base/Documentation/latest/User/MonitoringRecurringSituations for some more information..

Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...