Getting Data In

How to set up an alert on all search heads if any universal forwarder has not sent data for a certain amount of time?

brod_geico
Path Finder

I need to setup an alert on all search heads if any universal forwarder has not sent data in last 6 or 4 hours. The alerts have to trigger and send an email with output of missing hosts.
I have tried to use this one but it is not working.
|metadata type=hosts index=*| table host lastTime | where lastTimerelative_time(now(),"-30d@d")
| convert timeformat="%Y%m%d" ctime(lastTime) AS LastTime

0 Karma

lguinn2
Legend

Well, the reason could be that the where command is looking for a "last time" of over 30 days ago - and you have a typo.

Try this

|metadata type=hosts index=*
| table host lastTime
| where lastTime < relative_time(now(),"-4h")
| eval lastTime = strftime(lastTime, "%x %X")
0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...