<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Alert False Positives in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-Alert-False-Positives/m-p/582299#M13428</link>
    <description>&lt;P&gt;How would that be practically different than what I've already tried, which is 6:15 looking back 8 minutes?&amp;nbsp; The file always arrives at XX:10:05&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jan 2022 17:37:01 GMT</pubDate>
    <dc:creator>adzg</dc:creator>
    <dc:date>2022-01-24T17:37:01Z</dc:date>
    <item>
      <title>Splunk Alert False Positives</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alert-False-Positives/m-p/582289#M13426</link>
      <description>&lt;P&gt;I have an alert that runs every 10 minutes from 6am-3pm PST.&amp;nbsp; It checks to see if a file has arrived within the last few minutes (file arrives at 6:10, check for file at 6:12 with 4 minute timeframe).&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that every day, I get 1-3 false positive alerts.&amp;nbsp; I get an email saying that a file didn't arrive on time but when I go to perform the exact search with the hardcoded timeframe in question, the file did arrive on time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone ever run into this problem? Is this an issue with the alert scheduler?&amp;nbsp; I tried moving the alert back to give the file time to process in the system (file arrives at 6:10, check for file at 6:15 with 8 minute timeframe) but to no avail.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 17:08:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alert-False-Positives/m-p/582289#M13426</guid>
      <dc:creator>adzg</dc:creator>
      <dc:date>2022-01-24T17:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alert False Positives</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alert-False-Positives/m-p/582297#M13427</link>
      <description>&lt;P&gt;set it up at 6: 15 and let it check for last 10 min&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 17:33:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alert-False-Positives/m-p/582297#M13427</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-24T17:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alert False Positives</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alert-False-Positives/m-p/582299#M13428</link>
      <description>&lt;P&gt;How would that be practically different than what I've already tried, which is 6:15 looking back 8 minutes?&amp;nbsp; The file always arrives at XX:10:05&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 17:37:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alert-False-Positives/m-p/582299#M13428</guid>
      <dc:creator>adzg</dc:creator>
      <dc:date>2022-01-24T17:37:01Z</dc:date>
    </item>
  </channel>
</rss>

