<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bug in alert condition when summary index enabled? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53181#M518</link>
    <description>&lt;P&gt;Although this is expected behavior, what if you are trying to have an email alert action and summary indexing in the same saved search? By forcing the "always" condition, emails alerts will trigger every time the search runs.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Sep 2014 18:24:50 GMT</pubDate>
    <dc:creator>jds123</dc:creator>
    <dc:date>2014-09-16T18:24:50Z</dc:date>
    <item>
      <title>Bug in alert condition when summary index enabled?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53179#M516</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;If you create a saved search in the web interface and then set the alert condition to 'if custom condition is met' then enter a custom condition search.&lt;/P&gt;

&lt;P&gt;See second image here &lt;A href="http://imgur.com/a/qIe8z"&gt;http://imgur.com/a/qIe8z&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Then before pressing submit you tick enable to summary indexing. This resets the settings you made above.&lt;/P&gt;

&lt;P&gt;See first image here &lt;A href="http://imgur.com/a/qIe8z"&gt;http://imgur.com/a/qIe8z&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I have tested this on two different instances of Splunk (5.0.2 and 5.0.1) and the bug exists on both versions.&lt;/P&gt;

&lt;P&gt;Worse the issue also happens when you go back in to edit the search. Even when 'if custom condition is met' is set in the savedsearches.conf it will reset back if summary indexing is enabled. So if the user does not know about this bug they will lose their alert condition settings.&lt;/P&gt;

&lt;P&gt;Are others seeing this with their versions of Splunk?&lt;/P&gt;

&lt;P&gt;I have submitted this as a bug but was curious if others can reproduce?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2013 00:23:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53179#M516</guid>
      <dc:creator>phoenixdigital</dc:creator>
      <dc:date>2013-06-03T00:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: Bug in alert condition when summary index enabled?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53180#M517</link>
      <description>&lt;P&gt;This is not a bug but an expected behavior because summary indexing for an alert cannot be conditional.&lt;BR /&gt;
If you want to use other alert conditions, you must disable summary indexing.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2013 19:04:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53180#M517</guid>
      <dc:creator>mpawar_splunk</dc:creator>
      <dc:date>2013-09-27T19:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: Bug in alert condition when summary index enabled?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53181#M518</link>
      <description>&lt;P&gt;Although this is expected behavior, what if you are trying to have an email alert action and summary indexing in the same saved search? By forcing the "always" condition, emails alerts will trigger every time the search runs.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2014 18:24:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53181#M518</guid>
      <dc:creator>jds123</dc:creator>
      <dc:date>2014-09-16T18:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Bug in alert condition when summary index enabled?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53182#M519</link>
      <description>&lt;P&gt;No way to add the "if number of events" ??? &lt;BR /&gt;
It is very important to get this&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 15:30:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53182#M519</guid>
      <dc:creator>jrodriguezap</dc:creator>
      <dc:date>2014-10-09T15:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: Bug in alert condition when summary index enabled?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53183#M520</link>
      <description>&lt;P&gt;Would it work to use &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Loadjob"&gt;loadjob&lt;/A&gt; or &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Savedsearch"&gt;savedsearch&lt;/A&gt; commands to pull up the recent run and conditionally alert upon that?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 13:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Bug-in-alert-condition-when-summary-index-enabled/m-p/53183#M520</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-08-03T13:01:34Z</dc:date>
    </item>
  </channel>
</rss>

