Chapter 8. Being Proactive – Creating Alerts
In this chapter, we will learn about the alerting capabilities within Splunk. You will learn about:
- Alerting on abnormal web page response times
- Alerting on errors during checkout in real time
- Alerting on abnormal user behavior
- Alerting on failure and triggering a scripted response
- Alerting when predicted sales exceed inventory
Introduction
Throughout the previous chapters in this book, you created a great deal of Splunk searches, including historic searches that look back over a period of time and real-time searches. In this chapter, you will learn about alerting—arguably, one of Splunk's most powerful features.
A key part of gaining complete operational intelligence is the ability to be proactive rather than reactive. Periodic, ad hoc searching of the data for certain conditions might provide some operational insight, but a better approach would be to continually monitor the data and know immediately when certain conditions...