How to do it...

Follow the steps in this recipe to create an alert on failure and a trigger a webhook driven alert response:

  1. Log in to your Splunk server and select the Operational Intelligence application.
  2. In the Search bar, enter the following search over Last 24 hours:
index=main sourcetype=access_combined status=503 
  1. The search will run, but might not produce any results if there are no results to display. This is OK. As in the previous recipes, click on the Save As dropdown and select Alert:
  2. A pop-up box will appear to provide the alert configuration options. Perform the following steps on this screen:

a. Enter cp08_webserver_failure_webhook ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.