Alerting

Log inactivity

harishd
Explorer

Hi

Is there a way to send an alert if there is no logs coming for more than 10min for a source type.

Regards,
Harish

Tags (2)

Ayn
Legend

Yes. Search for your sourcetype, save the search and create an alert from it, scheduled to run every 10 minutes. This is covered in the manual here: http://www.splunk.com/base/Documentation/latest/User/SchedulingSavedSearches

As alert criteria, choose that the number of events for your search should equal 0. If no events are recorded in the 10 minutes between the scheduled searches, the alert will be triggered.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...