<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert not triggering, please help! in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-not-triggering-please-help/m-p/558005#M10621</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235937"&gt;@imggnz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please check logs using below search?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=scheduler savedsearch_name=YOUR_ALERT_NAME&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KV&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jul 2021 07:55:34 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2021-07-01T07:55:34Z</dc:date>
    <item>
      <title>Alert not triggering, please help!</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-triggering-please-help/m-p/557736#M10617</link>
      <description>&lt;P&gt;I have the below alert&lt;/P&gt;&lt;P&gt;| tstats latest(_time) as latest where index=*rsa* earliest=-10m by index&lt;BR /&gt;| eval recent = if(latest &amp;gt; relative_time(now(),"-10m"),1,0), realLatest = strftime(latest,"%c")&lt;BR /&gt;| where recent = 0&lt;/P&gt;&lt;P&gt;triggering on a cron job (*/10 * * * *), set to alert when results are not equal to 0&lt;/P&gt;&lt;P&gt;I can force the query to return a result by modifying it to the below&lt;/P&gt;&lt;P&gt;| tstats latest(_time) as latest where index=*rsa* earliest=-0m by index&lt;BR /&gt;| eval recent = if(latest &amp;gt; relative_time(now(),"-0m"),1,0), realLatest = strftime(latest,"%c")&lt;BR /&gt;| where recent = 0&lt;/P&gt;&lt;P&gt;In both cases where the original query/alert returns a result (under the statistics tab), and the modified/forced query/alert does, a triggered alert does not seem to proc as well as the email and pagerduty notification actions also tied into the alert actions.&lt;/P&gt;&lt;P&gt;As far as I can tell this makes logical sense to me, can anybody please advise?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 02:56:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-triggering-please-help/m-p/557736#M10617</guid>
      <dc:creator>imggnz</dc:creator>
      <dc:date>2021-06-30T02:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Alert not triggering, please help!</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-triggering-please-help/m-p/558005#M10621</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235937"&gt;@imggnz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please check logs using below search?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=scheduler savedsearch_name=YOUR_ALERT_NAME&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KV&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 07:55:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-triggering-please-help/m-p/558005#M10621</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-07-01T07:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: Alert not triggering, please help!</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-triggering-please-help/m-p/558260#M10623</link>
      <description>&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t h"&gt;07&lt;/SPAN&gt;-05-2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10:20:10.544&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1200&lt;/SPAN&gt; &lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SavedSplunker&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;savedsearch_id=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;nobody&lt;/SPAN&gt;&lt;SPAN&gt;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;WestpacAlerts&lt;/SPAN&gt;&lt;SPAN&gt;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;WNZL_PROTECT_RSA_NO_LOGS&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;search_type=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;scheduled&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;user=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;m773827&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;app=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;WestpacAlerts&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;savedsearch_name=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;WNZL_PROTECT_RSA_NO_LOGS&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;priority=default&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;status=success&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;digest_mode=1&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;scheduled_time=1625437200&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;window_time=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;dispatch_time=1625437209&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;run_time=0.416&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;result_count=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;alert_actions=&lt;/SPAN&gt;&lt;SPAN&gt;"", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;sid=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;scheduler__m773827__WestpacAlerts__RMD5c7bcdf14062491da_at_1625437200_73932&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;suppressed=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;thread_id=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;AlertNotifierWorker-0&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;workload_pool=&lt;/SPAN&gt;&lt;SPAN&gt;""&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;^ When not triggered&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;07-05-2021 10:40:10.097 +1200 INFO SavedSplunker - savedsearch_id="nobody;WestpacAlerts;WNZL_PROTECT_RSA_NO_LOGS", search_type="scheduled", user="m773827", app="WestpacAlerts", savedsearch_name="WNZL_PROTECT_RSA_NO_LOGS", priority=default, status=success, digest_mode=1, scheduled_time=1625438400, window_time=0, dispatch_time=1625438407, run_time=0.418, result_count=1, alert_actions="email,pagerduty", sid="scheduler__m773827__WestpacAlerts__RMD5c7bcdf14062491da_at_1625438400_74194", suppressed=0, thread_id="AlertNotifierWorker-1", workload_pool=""&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;^ When triggered&lt;BR /&gt;&lt;BR /&gt;I have resolved this issue by changing the trigger action, previously it was set to trigger when results were greater than zero, I changed to not equal to zero and now it works. Odd considering both sets of logic would work in my mind.&lt;BR /&gt;&lt;BR /&gt;Thank you for your help KV!&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 22:52:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-triggering-please-help/m-p/558260#M10623</guid>
      <dc:creator>imggnz</dc:creator>
      <dc:date>2021-07-04T22:52:38Z</dc:date>
    </item>
  </channel>
</rss>

