December 2014
Beginner to intermediate
344 pages
7h 34m
English
We've looked at scheduled alerts in detail in this chapter, so now, let's take a look at Splunk's ability to provide real-time alerts.
With real-time searching, you can search for events before they are indexed and preview the results as the events stream in. Based on real-time searches, you can create alerts that run continuously in the background to deliver timelier notifications than alerts that are based on scheduled searches.
In a similar fashion, in order to create a scheduled alert, we need to do the following to create a real-time alert:
Read now
Unlock full access