<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic System Tagger for McAfee ePO's jobs are incomplete due to maximum amount of time allowed in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/System-Tagger-for-McAfee-ePO-s-jobs-are-incomplete-due-to/m-p/341664#M41237</link>
    <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;we try to integrate System Tagger for McAfee ePO to apply tags in ePO DB. &lt;BR /&gt;
But the result is always incomplete - f.e. lt only  17 records were tagged from 300 required.&lt;BR /&gt;
It seems that the root cause was found in a scheduler.log "&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Reached maximum amount of time allowed to spend in per-result alerts... max_alerts_time=300 (seconds), fired_alerts=17&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;So I have 2 questions:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Is it normal that only 15-20 records may be tagged during 5 minutes? &lt;/LI&gt;
&lt;LI&gt;How to increase  the &lt;EM&gt;maximum amount of time allowed to spend in per-result alerts&lt;/EM&gt;?&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:15:29 GMT</pubDate>
    <dc:creator>evelenke</dc:creator>
    <dc:date>2020-09-29T17:15:29Z</dc:date>
    <item>
      <title>System Tagger for McAfee ePO's jobs are incomplete due to maximum amount of time allowed</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/System-Tagger-for-McAfee-ePO-s-jobs-are-incomplete-due-to/m-p/341664#M41237</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;we try to integrate System Tagger for McAfee ePO to apply tags in ePO DB. &lt;BR /&gt;
But the result is always incomplete - f.e. lt only  17 records were tagged from 300 required.&lt;BR /&gt;
It seems that the root cause was found in a scheduler.log "&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Reached maximum amount of time allowed to spend in per-result alerts... max_alerts_time=300 (seconds), fired_alerts=17&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;So I have 2 questions:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Is it normal that only 15-20 records may be tagged during 5 minutes? &lt;/LI&gt;
&lt;LI&gt;How to increase  the &lt;EM&gt;maximum amount of time allowed to spend in per-result alerts&lt;/EM&gt;?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:15:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/System-Tagger-for-McAfee-ePO-s-jobs-are-incomplete-due-to/m-p/341664#M41237</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2020-09-29T17:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: System Tagger for McAfee ePO's jobs are incomplete due to maximum amount of time allowed</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/System-Tagger-for-McAfee-ePO-s-jobs-are-incomplete-due-to/m-p/341665#M41238</link>
      <description>&lt;P&gt;Resolved with adding to system/local/limits.conf:&lt;/P&gt;

&lt;P&gt;[scheduler]&lt;BR /&gt;
max_per_result_alerts_time = 0&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/System-Tagger-for-McAfee-ePO-s-jobs-are-incomplete-due-to/m-p/341665#M41238</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2020-09-29T17:36:57Z</dc:date>
    </item>
  </channel>
</rss>

