<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Per - result Alert in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Per-result-Alert/m-p/702916#M12153</link>
    <description>&lt;P&gt;I am a grad student and I recently gave a quiz on splunk. There was a true/false question.&lt;/P&gt;&lt;P&gt;Q: Splunk Alerts can be created to monitor machine data in real-time, alerting of an event as soon as it logged by the host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I marked it as false because it should be "as soon as the event gets indexed by Splunk" instead of "as soon as the event gets logged by the host".&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have raised a question because I was not awarded marks for this question. But the counter was "Per-result triggering helps to achieve this". But isn't it basic that Splunk can only read the indexed data? Can anyone please verify if I'm correct?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Oct 2024 00:29:30 GMT</pubDate>
    <dc:creator>rvnk</dc:creator>
    <dc:date>2024-10-28T00:29:30Z</dc:date>
    <item>
      <title>Per - result Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Per-result-Alert/m-p/702916#M12153</link>
      <description>&lt;P&gt;I am a grad student and I recently gave a quiz on splunk. There was a true/false question.&lt;/P&gt;&lt;P&gt;Q: Splunk Alerts can be created to monitor machine data in real-time, alerting of an event as soon as it logged by the host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I marked it as false because it should be "as soon as the event gets indexed by Splunk" instead of "as soon as the event gets logged by the host".&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have raised a question because I was not awarded marks for this question. But the counter was "Per-result triggering helps to achieve this". But isn't it basic that Splunk can only read the indexed data? Can anyone please verify if I'm correct?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 00:29:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Per-result-Alert/m-p/702916#M12153</guid>
      <dc:creator>rvnk</dc:creator>
      <dc:date>2024-10-28T00:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Per - result Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Per-result-Alert/m-p/702917#M12154</link>
      <description>&lt;P&gt;Real-time searches see events before they are indexed.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 00:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Per-result-Alert/m-p/702917#M12154</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-10-28T00:39:06Z</dc:date>
    </item>
  </channel>
</rss>

