<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is Splunk Alert not triggering for every result? in Other Usage</title>
    <link>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657375#M1366</link>
    <description>&lt;P&gt;I have configure a splunk alert with alert condition to Trigger for each result. But every time I only get the alert for only one of those results. Any idea why?&lt;/P&gt;
&lt;P&gt;Below is the screenshot of the alert:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-09-12 at 7.10.03 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27152iA1FA713E5E817598/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-09-12 at 7.10.03 PM.png" alt="Screenshot 2023-09-12 at 7.10.03 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And below is a sample result from the alert query&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nytins_0-1694560421725.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27153iDE00C8E0A4FFBA8B/image-size/large?v=v2&amp;amp;px=999" role="button" title="nytins_0-1694560421725.png" alt="nytins_0-1694560421725.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Sep 2023 16:36:21 GMT</pubDate>
    <dc:creator>nytins</dc:creator>
    <dc:date>2023-09-14T16:36:21Z</dc:date>
    <item>
      <title>Why is Splunk Alert not triggering for every result?</title>
      <link>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657375#M1366</link>
      <description>&lt;P&gt;I have configure a splunk alert with alert condition to Trigger for each result. But every time I only get the alert for only one of those results. Any idea why?&lt;/P&gt;
&lt;P&gt;Below is the screenshot of the alert:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-09-12 at 7.10.03 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27152iA1FA713E5E817598/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-09-12 at 7.10.03 PM.png" alt="Screenshot 2023-09-12 at 7.10.03 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And below is a sample result from the alert query&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nytins_0-1694560421725.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27153iDE00C8E0A4FFBA8B/image-size/large?v=v2&amp;amp;px=999" role="button" title="nytins_0-1694560421725.png" alt="nytins_0-1694560421725.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 16:36:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657375#M1366</guid>
      <dc:creator>nytins</dc:creator>
      <dc:date>2023-09-14T16:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alert not triggering for every result</title>
      <link>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657391#M1367</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Have you already look from internal logs what has happened? There should be entries about fire of this alert.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 06:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657391#M1367</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-09-13T06:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alert not triggering for every result</title>
      <link>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657392#M1368</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/155815"&gt;@nytins&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first, using yesterday as Time Range, if you schedule your alert at 10:00 and at 19:00 you have the same result in both the runs.&lt;/P&gt;&lt;P&gt;For the issue, what does it happen if you use "Once"?&lt;/P&gt;&lt;P&gt;Then are you shure that the Trigger action you configured can manage more than one result? I don't know PagerDuty.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 06:32:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657392#M1368</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-13T06:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alert not triggering for every result</title>
      <link>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657499#M1369</link>
      <description>&lt;P&gt;Both "Once" and "For each result" behaves the same way for me. In both cases, I got the alert with only one event from the results. I am assuming PagerDuty doesn't support multiple results.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 22:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657499#M1369</guid>
      <dc:creator>nytins</dc:creator>
      <dc:date>2023-09-13T22:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alert not triggering for every result</title>
      <link>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657500#M1370</link>
      <description>&lt;P&gt;I don't have access to splunk servers, these are managed by a central team. Are these logs available to search within splunk? If yes, any how how can I search for it?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 22:58:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657500#M1370</guid>
      <dc:creator>nytins</dc:creator>
      <dc:date>2023-09-13T22:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alert not triggering for every result</title>
      <link>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657531#M1371</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/155815"&gt;@nytins&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, I don't know PagerDuty and probably the issue is the it doesn't permits multiple values.&lt;/P&gt;&lt;P&gt;If you don't have many results, you could create a workaround like the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;create a lookup (called e.g. PageDuty_temp.csv),&lt;/LI&gt;&lt;LI&gt;save your results in this lookup,&lt;/LI&gt;&lt;LI&gt;create a new alert that:&lt;UL&gt;&lt;LI&gt;searches on this lookup,&lt;/LI&gt;&lt;LI&gt;takes only the first value,&lt;/LI&gt;&lt;LI&gt;send a message to PagerDuty,&lt;/LI&gt;&lt;LI&gt;removes the used value from the lookup.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 06:23:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657531#M1371</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-14T06:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alert not triggering for every result</title>
      <link>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657534#M1372</link>
      <description>&lt;P&gt;Those are stored into _internal index. If you are not part of splunk admin team, you probably haven't access to it. You could try&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal&lt;/LI-CODE&gt;&lt;P&gt;To see if you can see events in that index and if you can then you can try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="_internal" component=SavedSplunker sourcetype="scheduler" thread_id="AlertNotifier*" NOT (alert_actions="summary_index" OR alert_actions="") app!=splunk_instrumentation 
| fields _time app result_count status alert_actions user savedsearch_name splunk_server_group 
| stats earliest(_time) as _time count as run_cnt sum(result_count) as result_count values(alert_actions) as alert_actions values(splunk_server_group) as splunk_server_group by app, savedsearch_name user status 
| table _time, run_cnt, app, savedsearch_name user status result_count alert_actions splunk_server_group&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;It shows alerts which has previously run and what has happen.&lt;/P&gt;&lt;P&gt;If you haven't access to internal logs, then you should ask from your Splunk admin team, that they will check what has happened.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 06:40:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Why-is-Splunk-Alert-not-triggering-for-every-result/m-p/657534#M1372</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-09-14T06:40:43Z</dc:date>
    </item>
  </channel>
</rss>

