Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to edit my search to find if a service is down, then trigger an alert only if the status is still down 1 minute later?

$
0
0
Hi , We have search that runs for every minute, and if in case it found any Service is down, it triggers an alert. However, we are thinking to enhance the search in a way that search should run for every 1 min interval, and if it finds a service down, it should not trigger an alert. Instead, it should wait for one more minute and if it still gets the status as "Service Down", then it should trigger. Below is our basic search: index =index1 sourcetype=WMI Caption="*" host=WGP | stats latest(State) AS State by _time host Name | rename Name as Service | search State=Stopped | eval currentTime=now()

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>