Release Notes

 


Scalable alerting

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Scalable alerting

Advanced conditional alerting

This feature allows users to specify more complex conditions for triggering alerts. In previous versions of Splunk, users were limited to setting alerting conditions based on the number of events, sources, and hosts that appeared in a result set. Now, for any result set, a user can specify a search as a condition. If that search returns one or more events (ie true), an alert containing the original result set would be triggered.

Learn more about advanced conditional alerting in the Admin Manual.

Alerts over large data sets

This feature includes Splunk's ability to run alerts concurrently and over larger datasets. This is an extension of Splunk's Analyze large datasets feature.

Splunk's back-end processing and handling of alerts has been improved substantially, allowing users to run alerts concurrently (in previous versions they were run serially).

Benefits

This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.