<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Real Time Alerting in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95236#M1369</link>
    <description>&lt;P&gt;If the search works manually, then it is not a license issue.  When you have to many violations in a 30 day period then you can't search at all.&lt;/P&gt;

&lt;P&gt;Your start time should be rt-1m &lt;BR /&gt;
Consider setting the alert condition to trigger on number of results greater than 1.  &lt;/P&gt;

&lt;P&gt;Don't test the search from the search app, test it by selecting Run from the Manager &amp;gt; Searches and Reports.&lt;/P&gt;

&lt;P&gt;You can also reconfigure to run as a scheduled search that runs every minute, and trigger on number of results greater than 1.&lt;/P&gt;</description>
    <pubDate>Sun, 13 Oct 2013 10:55:58 GMT</pubDate>
    <dc:creator>lukejadamec</dc:creator>
    <dc:date>2013-10-13T10:55:58Z</dc:date>
    <item>
      <title>Real Time Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95234#M1367</link>
      <description>&lt;P&gt;I'm working on configuring some basic alerts for the a system. This is splunk 5.0.2 on Windows 2008 R2.&lt;/P&gt;

&lt;P&gt;The search is very simple:&lt;/P&gt;

&lt;P&gt;Source = "E:\Program Files*" High&lt;/P&gt;

&lt;P&gt;which returns results every time, now before fine tuning the search I wan to confirm that the alerts will fire correctly through alert manager and SMTP.&lt;/P&gt;

&lt;P&gt;My parameters for the alert is as follows:&lt;BR /&gt;
Start Time rt     End time rt&lt;/P&gt;

&lt;P&gt;Alert&lt;BR /&gt;
Condition Always&lt;/P&gt;

&lt;P&gt;Alert Mode once per result&lt;/P&gt;

&lt;P&gt;no throttling&lt;/P&gt;

&lt;P&gt;Expiration 24 hours&lt;/P&gt;

&lt;P&gt;Severity High&lt;/P&gt;

&lt;P&gt;Send email "valid email address with subject etc"&lt;/P&gt;

&lt;P&gt;Tracking enabled&lt;/P&gt;

&lt;P&gt;This alert should be overloading my inbox with emails, but it's not showing in alert manager even. The only thing I can think of is we currently have license violations on this instance, but searching and alerting are not yet disabled. The capacity for the day is blown though.&lt;/P&gt;

&lt;P&gt;Any help is appreciated!&lt;/P&gt;

&lt;P&gt;EDIT: Turned out that we had way to many saved searches (that were no longer relevant since we are making out alerts generic) I cleared them out of the saved searches .conf file and things started running better. I also had upgraded from 5.02 to 5.05.&lt;/P&gt;

&lt;P&gt;Thanks for your help everyone! &lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2013 18:22:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95234#M1367</guid>
      <dc:creator>tnconners</dc:creator>
      <dc:date>2013-10-11T18:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95235#M1368</link>
      <description>&lt;P&gt;Splunk regulates your license usage by tracking license violations. If you go over 500 MB/day more than 3 times in a 30 day period, Splunk continues to index your data, but disables search functionality until you are back down to 3 or fewer warnings in the 30 day period.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Oct 2013 01:31:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95235#M1368</guid>
      <dc:creator>exd42062</dc:creator>
      <dc:date>2013-10-13T01:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95236#M1369</link>
      <description>&lt;P&gt;If the search works manually, then it is not a license issue.  When you have to many violations in a 30 day period then you can't search at all.&lt;/P&gt;

&lt;P&gt;Your start time should be rt-1m &lt;BR /&gt;
Consider setting the alert condition to trigger on number of results greater than 1.  &lt;/P&gt;

&lt;P&gt;Don't test the search from the search app, test it by selecting Run from the Manager &amp;gt; Searches and Reports.&lt;/P&gt;

&lt;P&gt;You can also reconfigure to run as a scheduled search that runs every minute, and trigger on number of results greater than 1.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Oct 2013 10:55:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95236#M1369</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-13T10:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95237#M1370</link>
      <description>&lt;P&gt;There was a problem with 5.0.2 that affected real time alerts and was fixed in 5.0.3. It's in the 5.0.3 release notes as "Real Time Alerts not working consistently in 5.0.2. (SPL-62129)". Might be worth taking a brief outage to upgrade to 5.0.5. Good luck!&lt;/P&gt;</description>
      <pubDate>Sun, 13 Oct 2013 20:26:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95237#M1370</guid>
      <dc:creator>jtacy</dc:creator>
      <dc:date>2013-10-13T20:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95238#M1371</link>
      <description>&lt;P&gt;Tried all of your suggestions, Still no luck. I also upgraded as jtacy suggested. It seems like my scheduled searches are never starting. (I've watched the jobs screen).&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2013 17:54:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95238#M1371</guid>
      <dc:creator>tnconners</dc:creator>
      <dc:date>2013-10-14T17:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Alerting</title>
      <link>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95239#M1372</link>
      <description>&lt;P&gt;Try creating a new scheduled search from scratch.  I had one that behaved like this once, and I had to create a new search to fix it.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2013 16:37:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-Time-Alerting/m-p/95239#M1372</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-15T16:37:32Z</dc:date>
    </item>
  </channel>
</rss>

