From the course: Splunk for Security Analytics and Monitoring

Unlock the full course today

Join today to access over 24,900 courses taught by industry experts.

Managing Splunk alerts

Managing Splunk alerts

- [Narrator] So we've configured Splunk to ingest data from a number of different forwarders and local files, and also we know that it gets indexed and is thus searchable. So we could search for anything we like. For example, here on my Splunk Cloud Platform I've got a dashboard with a search saved as a report showing me the number of HTTP 404 errors. And we've even set that dashboard as the default homepage when we launch our Splunk Cloud Platform web console. So that's great. We sign in, we've got little chart lines that show us when we've got 404 errors. However, wouldn't it be great if it would notify us when that occurs at that time? Or at least hourly. So that way we wouldn't have to come back and always look at our dashboard visualization as great as it is. So what we're going to do then, is start here in Splunk Cloud by clicking Search and Reporting over on the left. And I'm going to run this search.…

Contents