Splunk Search

Search within last 5 minutes

Infinity8
New Member

Please help I am trying to make a search for a string in the past five minutes and if there are over 100 I want an email alert.

Many Thanks!

Tags (3)
0 Karma
1 Solution

Brian_Osburn
Builder

What type of information are you looking for? What does your data look like?

Searches are pretty basic - figure out what you want to look for, save it and set up an alert.

Taking a look at http://www.splunk.com/base/Documentation/latest/User/AboutSearch and http://www.splunk.com/base/Documentation/latest/User/MonitoringRecurringSituations for some more information..

View solution in original post

snowmizer
Communicator

The docs Brian reference are good places to start.

0 Karma

Brian_Osburn
Builder

What type of information are you looking for? What does your data look like?

Searches are pretty basic - figure out what you want to look for, save it and set up an alert.

Taking a look at http://www.splunk.com/base/Documentation/latest/User/AboutSearch and http://www.splunk.com/base/Documentation/latest/User/MonitoringRecurringSituations for some more information..

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...