Getting ready

To step through this recipe, you will need a running Splunk Enterprise server, with the sample data loaded from Chapter 1, Play Time - Getting Data In, and should have completed the earlier recipes in this chapter. You should also be familiar with navigating the Splunk user interface. You should also have configured your email server to work with Splunk so that Splunk can send emails to specified addresses.

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.