<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic a real-time alert error in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/a-real-time-alert-error/m-p/541313#M10244</link>
    <description>&lt;P&gt;Hello, I want to create a real-time alert. I call the rest interface：&lt;/P&gt;&lt;P&gt;https://&amp;lt;host&amp;gt;:&amp;lt;mPort&amp;gt;/services/saved/searches&lt;/P&gt;&lt;P&gt;, and the parameter is:&amp;nbsp; &amp;nbsp;is_ visible=1&amp;amp;cron_ Schedule = * * * * * &amp;amp; Description = real time data 25 &amp;amp; alert_ comparator=greater than&amp;amp; alert.digest_ mode=0&amp;amp; action.webhook.param .url= www.ceshi:8099/splunk/webhook/alert&amp;amp; dispatch.earliest_ time=rt-60s&amp;amp;alert_ threshold=30&amp;amp;realtime_ schedule=true&amp;amp;alert_ type=number of events&amp;amp;search=ip=192.168.21.222&amp;amp; alert.expires=15d&amp;amp;name=417218432270925848&amp;amp;output_ mode=json&amp;amp; dispatch.latest_ time=rt-0s&amp;amp;disabled=0&amp;amp;is_ scheduled=true&amp;amp;actions=webhook&lt;/P&gt;&lt;P&gt;However, the error display is returned: 400 bad request: [{"messages": [{"type": "error", "text": "per result alert throttling require at least one throttling field, use * to throttle on all fields"}]}]，&lt;/P&gt;&lt;P&gt;Is there a problem with the parameter I passed? Or is there an error in the SPL statement?&lt;/P&gt;</description>
    <pubDate>Thu, 25 Feb 2021 08:02:32 GMT</pubDate>
    <dc:creator>splunk-user</dc:creator>
    <dc:date>2021-02-25T08:02:32Z</dc:date>
    <item>
      <title>a real-time alert error</title>
      <link>https://community.splunk.com/t5/Alerting/a-real-time-alert-error/m-p/541313#M10244</link>
      <description>&lt;P&gt;Hello, I want to create a real-time alert. I call the rest interface：&lt;/P&gt;&lt;P&gt;https://&amp;lt;host&amp;gt;:&amp;lt;mPort&amp;gt;/services/saved/searches&lt;/P&gt;&lt;P&gt;, and the parameter is:&amp;nbsp; &amp;nbsp;is_ visible=1&amp;amp;cron_ Schedule = * * * * * &amp;amp; Description = real time data 25 &amp;amp; alert_ comparator=greater than&amp;amp; alert.digest_ mode=0&amp;amp; action.webhook.param .url= www.ceshi:8099/splunk/webhook/alert&amp;amp; dispatch.earliest_ time=rt-60s&amp;amp;alert_ threshold=30&amp;amp;realtime_ schedule=true&amp;amp;alert_ type=number of events&amp;amp;search=ip=192.168.21.222&amp;amp; alert.expires=15d&amp;amp;name=417218432270925848&amp;amp;output_ mode=json&amp;amp; dispatch.latest_ time=rt-0s&amp;amp;disabled=0&amp;amp;is_ scheduled=true&amp;amp;actions=webhook&lt;/P&gt;&lt;P&gt;However, the error display is returned: 400 bad request: [{"messages": [{"type": "error", "text": "per result alert throttling require at least one throttling field, use * to throttle on all fields"}]}]，&lt;/P&gt;&lt;P&gt;Is there a problem with the parameter I passed? Or is there an error in the SPL statement?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 08:02:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/a-real-time-alert-error/m-p/541313#M10244</guid>
      <dc:creator>splunk-user</dc:creator>
      <dc:date>2021-02-25T08:02:32Z</dc:date>
    </item>
  </channel>
</rss>

