Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How can I identify hosts that don't have any events over a 4-hour period and create an alert?

$
0
0
I want to identify any host that doesn't have any events over a four hour period and create an alert. Having trouble extracting the individual host. index=ind1 | timechart span=4h count by host | where count = 0 | table host count time

Viewing all articles
Browse latest Browse all 47296

Trending Articles