<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Real time alerts in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77766#M1093</link>
    <description>&lt;P&gt;Awesome. Well I am glad I was able to help. Take it easy. &lt;/P&gt;</description>
    <pubDate>Fri, 04 Jan 2013 17:54:32 GMT</pubDate>
    <dc:creator>BobDaMann</dc:creator>
    <dc:date>2013-01-04T17:54:32Z</dc:date>
    <item>
      <title>Real time alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77762#M1089</link>
      <description>&lt;P&gt;Im having problems with the real time alerts, splunk is not sending all the events by email, it works fine in the first 3 minuts, but after that Im not getting any email or events in the alert manager, but if i schedule that same search but dont make it rt search it does work and I get all my alerts in my inbox.&lt;BR /&gt;
This problem started after I upgrade to Splunk 5, with Splunk 4.x I didnt have that problem&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2013 23:16:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77762#M1089</guid>
      <dc:creator>christinmb</dc:creator>
      <dc:date>2013-01-03T23:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77763#M1090</link>
      <description>&lt;P&gt;Could you provide more information? I'd like to know a little bit more about the alert you have set up.&lt;/P&gt;

&lt;P&gt;Perhaps a screenshot of the alert settings? &lt;/P&gt;

&lt;P&gt;Are you using throttling? &lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2013 04:49:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77763#M1090</guid>
      <dc:creator>BobDaMann</dc:creator>
      <dc:date>2013-01-04T04:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77764#M1091</link>
      <description>&lt;P&gt;&lt;A href="https://dl.dropbox.com/u/97076067/df.png"&gt;https://dl.dropbox.com/u/97076067/df.png&lt;/A&gt; thats the configuration I have&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2013 14:41:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77764#M1091</guid>
      <dc:creator>christinmb</dc:creator>
      <dc:date>2013-01-04T14:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77765#M1092</link>
      <description>&lt;P&gt;It was an error in the "per results throttling fields" and the alerting mode, thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2013 17:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77765#M1092</guid>
      <dc:creator>christinmb</dc:creator>
      <dc:date>2013-01-04T17:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77766#M1093</link>
      <description>&lt;P&gt;Awesome. Well I am glad I was able to help. Take it easy. &lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2013 17:54:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-time-alerts/m-p/77766#M1093</guid>
      <dc:creator>BobDaMann</dc:creator>
      <dc:date>2013-01-04T17:54:32Z</dc:date>
    </item>
  </channel>
</rss>

