<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert randomly stops working in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/564614#M12953</link>
    <description>&lt;P&gt;Hi .. under alert type do you have Scheduled or Real-time?&lt;BR /&gt;&lt;BR /&gt;Also, not sure if you have a search head cluster and a monitoring console/DMC. That might show you skipped searches etc.&lt;/P&gt;&lt;P&gt;Finally there are records for the saved search in the audit log. This might help you see if the the scheduler believes that the jobs were completed.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Aug 2021 22:32:06 GMT</pubDate>
    <dc:creator>burwell</dc:creator>
    <dc:date>2021-08-24T22:32:06Z</dc:date>
    <item>
      <title>Alert randomly stops working</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/564503#M12952</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am seeing a strange issue where occaisionally one of my alerts stop working ( not always the same one ). When this issue is happening I can see the searches running but there are no triggers happening for the alert even when manually running the search finds the events.&lt;/P&gt;&lt;P&gt;I have tweaked the searches to make sure I am not falling foul of the _indextime vs _time issue caused by alerts arriving outside the search window.&lt;/P&gt;&lt;P&gt;It appears that the search just stops triggering and it starts again when I Disable/Enable the search.&lt;/P&gt;&lt;P&gt;Anyone else seeing this or have any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 10:34:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/564503#M12952</guid>
      <dc:creator>mscomms</dc:creator>
      <dc:date>2021-08-24T10:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Alert randomly stops working</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/564614#M12953</link>
      <description>&lt;P&gt;Hi .. under alert type do you have Scheduled or Real-time?&lt;BR /&gt;&lt;BR /&gt;Also, not sure if you have a search head cluster and a monitoring console/DMC. That might show you skipped searches etc.&lt;/P&gt;&lt;P&gt;Finally there are records for the saved search in the audit log. This might help you see if the the scheduler believes that the jobs were completed.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 22:32:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/564614#M12953</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2021-08-24T22:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Alert randomly stops working</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/564654#M12960</link>
      <description>&lt;P&gt;Wer are seeing the same issue with both but are in the process of migrating from Real-Time to scheduled as the scheduled gives faster results&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 07:56:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/564654#M12960</guid>
      <dc:creator>mscomms</dc:creator>
      <dc:date>2021-08-25T07:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alert randomly stops working</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/564883#M12963</link>
      <description>&lt;P&gt;As I said above we are seeing this issue with Real-Time and Scheduled, I have the issue happening right now witha a Real-Time search in my test environment.&lt;/P&gt;&lt;P&gt;I am firing test events into an existing index, I can see them arriving in the index, if I run the search in the alert as a manual search it shows the event but the the action isn't triggering and when I run&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;index="_internal" sourcetype!=splunkd_remote_searches savedsearch savedsearch_name=NOC_Alcatel result_count=1&lt;BR /&gt;&lt;BR /&gt;I see hits from my first few test alerts but nothing from after it stopped responding.&lt;/P&gt;&lt;P&gt;Yes we are running a 3 node cluster.&lt;/P&gt;&lt;P&gt;I'm not seeing any issues in DMC the skip ratio over the last 4 hours is 0%&lt;BR /&gt;&lt;BR /&gt;I am seeing these every minute&lt;/P&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;08-26-2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10:59:01.230&lt;/SPAN&gt; +&lt;SPAN class="t"&gt;0100&lt;/SPAN&gt; &lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SHCMaster&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;delegate&lt;/SPAN&gt; &lt;SPAN class="t"&gt;search&lt;/SPAN&gt; &lt;SPAN class="t"&gt;job&lt;/SPAN&gt; &lt;SPAN class="t"&gt;requested&lt;/SPAN&gt; &lt;SPAN class="t"&gt;for&lt;/SPAN&gt; &lt;SPAN class="t"&gt;savedsearch_name=&lt;/SPAN&gt;"&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;NOC_Alcatel"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="shared-eventsviewer-list-body-row-selectedfields"&gt;&lt;UL class="condensed-selected-fields"&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="pr-l-sphead-03v.dcnlab.sset.local" href="https://splunkwaf.dcnlab.sset.local/en-GB/app/noc/search?q=search%20index%3D%22_internal%22%20sourcetype!%3Dsplunkd_remote_searches%20NOC_Alcatel&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.prefs.events.offset=420&amp;amp;sid=1629982950.1194872_FED91838-A38F-4845-AB5A-7BDD76E381A9#" target="_blank" rel="noopener"&gt;pr-l-sphead-03v.dcnlab.sset.local&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="/opt/splunk/var/log/splunk/splunkd.log" href="https://splunkwaf.dcnlab.sset.local/en-GB/app/noc/search?q=search%20index%3D%22_internal%22%20sourcetype!%3Dsplunkd_remote_searches%20NOC_Alcatel&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.prefs.events.offset=420&amp;amp;sid=1629982950.1194872_FED91838-A38F-4845-AB5A-7BDD76E381A9#" target="_blank" rel="noopener"&gt;/opt/splunk/var/log/splunk/splunkd.log&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="splunkd" href="https://splunkwaf.dcnlab.sset.local/en-GB/app/noc/search?q=search%20index%3D%22_internal%22%20sourcetype!%3Dsplunkd_remote_searches%20NOC_Alcatel&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.prefs.events.offset=420&amp;amp;sid=1629982950.1194872_FED91838-A38F-4845-AB5A-7BDD76E381A9#" target="_blank" rel="noopener"&gt;splunkd&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;08-26-2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10:59:01.230&lt;/SPAN&gt; +&lt;SPAN class="t"&gt;0100&lt;/SPAN&gt; &lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SHCMaster&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;realtime&lt;/SPAN&gt; &lt;SPAN class="t"&gt;search&lt;/SPAN&gt; &lt;SPAN class="t"&gt;savedsearch_name=NOC_Alcatel&lt;/SPAN&gt; &lt;SPAN class="t"&gt;selector=nobody&lt;/SPAN&gt;;&lt;SPAN class="t"&gt;noc&lt;/SPAN&gt;;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;NOC_Alcatel&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sid=rt_scheduler__admin__noc__RMD5aff146651f76f3cb_at_1629386520_7_5E69A627-7FCE-4CAE-A9C4-E72E65CBF04A&lt;/SPAN&gt; &lt;SPAN class="t"&gt;is&lt;/SPAN&gt; &lt;SPAN class="t"&gt;either&lt;/SPAN&gt; &lt;SPAN class="t"&gt;already&lt;/SPAN&gt; &lt;SPAN class="t"&gt;running&lt;/SPAN&gt; &lt;SPAN class="t"&gt;or&lt;/SPAN&gt; &lt;SPAN class="t"&gt;being&lt;/SPAN&gt; &lt;SPAN class="t"&gt;dispatched.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Ignoring&lt;/SPAN&gt; &lt;SPAN class="t"&gt;request.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="shared-eventsviewer-list-body-row-selectedfields"&gt;&lt;UL class="condensed-selected-fields"&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="pr-l-sphead-03v.dcnlab.sset.local" href="https://splunkwaf.dcnlab.sset.local/en-GB/app/noc/search?q=search%20index%3D%22_internal%22%20sourcetype!%3Dsplunkd_remote_searches%20NOC_Alcatel&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.prefs.events.offset=420&amp;amp;sid=1629982950.1194872_FED91838-A38F-4845-AB5A-7BDD76E381A9#" target="_blank" rel="noopener"&gt;pr-l-sphead-03v.dcnlab.sset.local&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="/opt/splunk/var/log/splunk/splunkd.log" href="https://splunkwaf.dcnlab.sset.local/en-GB/app/noc/search?q=search%20index%3D%22_internal%22%20sourcetype!%3Dsplunkd_remote_searches%20NOC_Alcatel&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.prefs.events.offset=420&amp;amp;sid=1629982950.1194872_FED91838-A38F-4845-AB5A-7BDD76E381A9#" target="_blank" rel="noopener"&gt;/opt/splunk/var/log/splunk/splunkd.log&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="splunkd" href="https://splunkwaf.dcnlab.sset.local/en-GB/app/noc/search?q=search%20index%3D%22_internal%22%20sourcetype!%3Dsplunkd_remote_searches%20NOC_Alcatel&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.prefs.events.offset=420&amp;amp;sid=1629982950.1194872_FED91838-A38F-4845-AB5A-7BDD76E381A9#" target="_blank" rel="noopener"&gt;splunkd&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN class="field-value"&gt;but I am also seeing these going back forever so I dont think they are anything to do with this issue&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 13:07:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/564883#M12963</guid>
      <dc:creator>mscomms</dc:creator>
      <dc:date>2021-08-26T13:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Alert randomly stops working</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/565009#M12966</link>
      <description>&lt;P&gt;I see nothing relating to this search in the audit.log&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 09:07:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-randomly-stops-working/m-p/565009#M12966</guid>
      <dc:creator>mscomms</dc:creator>
      <dc:date>2021-08-27T09:07:22Z</dc:date>
    </item>
  </channel>
</rss>

