<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert is not getting triggered in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199938#M12091</link>
    <description>&lt;P&gt;Alright!&lt;BR /&gt;
Select your app &lt;BR /&gt;
Run your search in the search bar and check if the results are showing up&lt;BR /&gt;
Save as alert and schedule the alert. Check the scheduler log for your alert&lt;/P&gt;</description>
    <pubDate>Sun, 18 Sep 2016 13:47:49 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2016-09-18T13:47:49Z</dc:date>
    <item>
      <title>Alert is not getting triggered</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199935#M12088</link>
      <description>&lt;P&gt;Hi People,&lt;/P&gt;

&lt;P&gt;I created a sample app which works with uploaded data in splunk. The data has almost 1700 rows. This data is fixed. I created an alert which is based on triggered condition. The condition is number of results. I added condition in alert is number of results &amp;gt;0 in last one minute. when I do simple search like source="sourcename". Results are returning my 1700 rows. &lt;BR /&gt;
But alert is not triggering. I don't see anything in alert  activity( Triggered alert).&lt;BR /&gt;
What am I missing here?&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;BR /&gt;
Bheem&lt;/P&gt;</description>
      <pubDate>Sat, 17 Sep 2016 17:50:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199935#M12088</guid>
      <dc:creator>bhepi01</dc:creator>
      <dc:date>2016-09-17T17:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Alert is not getting triggered</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199936#M12089</link>
      <description>&lt;P&gt;Few things to check :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Are you running the same search as in alert in the search bar with 1 minute time range?&lt;/LI&gt;
&lt;LI&gt;Try adding index= in the SPL. It's possible that your search is not searching any index by default. &lt;/LI&gt;
&lt;LI&gt;Do you see any entries in the scheduler log about this alert ?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Have a look at &lt;A href="http://wiki.splunk.com/Community:TroubleshootingScheduledSearches"&gt;http://wiki.splunk.com/Community:TroubleshootingScheduledSearches&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2016 04:09:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199936#M12089</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2016-09-18T04:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Alert is not getting triggered</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199937#M12090</link>
      <description>&lt;P&gt;I  tried with index= also , I did not  see any entries in scheduler log.&lt;/P&gt;

&lt;P&gt;PS: I did not understand first point. &lt;/P&gt;

&lt;P&gt;Please explain first point and I request to give some other points to debug this problem. &lt;/P&gt;

&lt;P&gt;I am tired of this &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2016 09:11:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199937#M12090</guid>
      <dc:creator>bhepi01</dc:creator>
      <dc:date>2016-09-18T09:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Alert is not getting triggered</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199938#M12091</link>
      <description>&lt;P&gt;Alright!&lt;BR /&gt;
Select your app &lt;BR /&gt;
Run your search in the search bar and check if the results are showing up&lt;BR /&gt;
Save as alert and schedule the alert. Check the scheduler log for your alert&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2016 13:47:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199938#M12091</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2016-09-18T13:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: Alert is not getting triggered</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199939#M12092</link>
      <description>&lt;P&gt;How much time do I need to select in scheduler alert ?&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2016 13:57:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-is-not-getting-triggered/m-p/199939#M12092</guid>
      <dc:creator>bhepi01</dc:creator>
      <dc:date>2016-09-18T13:57:14Z</dc:date>
    </item>
  </channel>
</rss>

