About Splunk alerts

As with many features of Splunk, alerts are powered by underlying searches. These underlying searches can either run on a schedule against historically indexed data or run against real-time data as it flows into Splunk. Alerts can then be triggered every time a search runs or when certain search conditions are met.

Additionally, all alerting in Splunk can be throttled so that alerts do not continuously fire if similar conditions are met repeatedly, and this will be covered later in the chapter.

Splunk has a dedicated manual for alerting, which can be found at https://docs.splunk.com/Documentation/Splunk/latest/Alert/Aboutalerts.

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.