<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Alerts failing to Trigger in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564626#M12955</link>
    <description>&lt;P&gt;I have a scheduled alert running every 15 minutes in the cron schedule.&lt;/P&gt;&lt;P&gt;I set trigger action as Email, ServiceNow ticket &amp;amp; MS Teams notification.&lt;/P&gt;&lt;P&gt;Here 80% of the alerts I am receiving successfully. But i am failing to receive the remaining 20% alerts in Email, ServiceNow tickets &amp;amp; MS Teams.&lt;/P&gt;&lt;P&gt;But when I am running the search I can able to find the result but I didn't receive the same alerts.&lt;/P&gt;&lt;P&gt;When I search scheduler logs&amp;nbsp; I didn't find any failure logs.&lt;/P&gt;&lt;P&gt;Please help here.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 04:33:24 GMT</pubDate>
    <dc:creator>alexspunkshell</dc:creator>
    <dc:date>2021-08-25T04:33:24Z</dc:date>
    <item>
      <title>Splunk Alerts failing to Trigger</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564626#M12955</link>
      <description>&lt;P&gt;I have a scheduled alert running every 15 minutes in the cron schedule.&lt;/P&gt;&lt;P&gt;I set trigger action as Email, ServiceNow ticket &amp;amp; MS Teams notification.&lt;/P&gt;&lt;P&gt;Here 80% of the alerts I am receiving successfully. But i am failing to receive the remaining 20% alerts in Email, ServiceNow tickets &amp;amp; MS Teams.&lt;/P&gt;&lt;P&gt;But when I am running the search I can able to find the result but I didn't receive the same alerts.&lt;/P&gt;&lt;P&gt;When I search scheduler logs&amp;nbsp; I didn't find any failure logs.&lt;/P&gt;&lt;P&gt;Please help here.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 04:33:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564626#M12955</guid>
      <dc:creator>alexspunkshell</dc:creator>
      <dc:date>2021-08-25T04:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts failing to Trigger</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564633#M12956</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;How is your alert defined? Verify the&amp;nbsp;&lt;STRONG&gt;Trigger Conditions&lt;/STRONG&gt; and make sure that these configs are correct.&lt;/P&gt;&lt;P&gt;You can use the schedule options:&amp;nbsp;&lt;STRONG&gt;Once&amp;nbsp;&lt;/STRONG&gt;OR&amp;nbsp;&lt;STRONG&gt;For each result.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If your alert return multiple results and you need to send an action for each result select the&amp;nbsp;&lt;STRONG&gt;For each result&amp;nbsp;&lt;/STRONG&gt;option, select&amp;nbsp;&lt;STRONG&gt;Once&amp;nbsp;&lt;/STRONG&gt;otherwise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can view the recent results of your scheduled alert on "Settings &amp;gt; Searches, Reports, and Alerts &amp;gt; Filter your alert &amp;gt; click on View Recent" for further troubleshooting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 05:31:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564633#M12956</guid>
      <dc:creator>danielcj</dc:creator>
      <dc:date>2021-08-25T05:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts failing to Trigger</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564636#M12957</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213178"&gt;@danielcj&lt;/a&gt;&amp;nbsp;Thanks for your reply.&lt;/P&gt;&lt;P&gt;How is your alert defined? - Number of results greater than 0&lt;/P&gt;&lt;P&gt;I see only "status=Done"&amp;nbsp;&lt;SPAN&gt;in&amp;nbsp; View Recent. I didn't see my failed alerts here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below is the screenshot of the alert.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexspunkshell_0-1629870323309.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15716i436C9AC255BAFA21/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexspunkshell_0-1629870323309.png" alt="alexspunkshell_0-1629870323309.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 05:47:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564636#M12957</guid>
      <dc:creator>alexspunkshell</dc:creator>
      <dc:date>2021-08-25T05:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts failing to Trigger</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564643#M12958</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;it seems that you have added Alert Throttling here. This means that it didn't fire again same alert within Suppress triggering for time, which you have 7 days. Can this be the reason for no fire alerts?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Alert/ThrottleAlerts" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Alert/ThrottleAlerts&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 06:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564643#M12958</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-08-25T06:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts failing to Trigger</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564982#M12965</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;I disabled the throttle now. But again the same issue persists.&lt;/P&gt;&lt;P&gt;When I check the index=_internal &amp;amp; scheduler logs it is showing the status as success. Whereas I didn't receive any alert ServiceNow/Email/MS teams.&lt;/P&gt;&lt;P&gt;Out of 10 alerts, I am receiving 8 alerts properly. 2 alerts always failing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 07:42:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-failing-to-Trigger/m-p/564982#M12965</guid>
      <dc:creator>alexspunkshell</dc:creator>
      <dc:date>2021-08-27T07:42:23Z</dc:date>
    </item>
  </channel>
</rss>

