<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: why alerts not working in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595101#M13778</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241629"&gt;@Pablo00&lt;/a&gt;&amp;nbsp;- Alerting is one of the feature which is not available in free license.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/MoreaboutSplunkFree" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/MoreaboutSplunkFree&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-------&lt;BR /&gt;I hope this helps!! Kindly upvote if it does.!!!&lt;/P&gt;</description>
    <pubDate>Mon, 25 Apr 2022 05:40:35 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2022-04-25T05:40:35Z</dc:date>
    <item>
      <title>Why alerts are not working?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595062#M13776</link>
      <description>&lt;P&gt;hello,&amp;nbsp;&lt;BR /&gt;I just started with splunk and I need your help. I am not sure why alerts not working for me&lt;/P&gt;
&lt;P&gt;this is an example ( looking for ping event +&amp;nbsp; PowerShell )&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Pablo00_2-1650797149373.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19275i01C12F98FE23698D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Pablo00_2-1650797149373.png" alt="Pablo00_2-1650797149373.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Pablo00_4-1650797195706.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19277i9FFB3BD4C1962911/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Pablo00_4-1650797195706.png" alt="Pablo00_4-1650797195706.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Pablo00_3-1650797170434.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19276i122DFDA673CCCC0C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Pablo00_3-1650797170434.png" alt="Pablo00_3-1650797170434.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I set up to send an email to my inbox ( Do i need to configure stmp or something? or it will working without any configuration?)&lt;/P&gt;
&lt;P&gt;also I cant see anything in Alet tab - just a comment&amp;nbsp; &amp;gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;There are no fired events for this alert.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am not sure what I am doing wrong, please help me if you can! Many thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;( I have 60days free splunk)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 15:05:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595062#M13776</guid>
      <dc:creator>Pablo00</dc:creator>
      <dc:date>2022-04-25T15:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: why alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595101#M13778</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241629"&gt;@Pablo00&lt;/a&gt;&amp;nbsp;- Alerting is one of the feature which is not available in free license.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/MoreaboutSplunkFree" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/MoreaboutSplunkFree&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-------&lt;BR /&gt;I hope this helps!! Kindly upvote if it does.!!!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 05:40:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595101#M13778</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-25T05:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: why alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595105#M13779</link>
      <description>&lt;P&gt;thanks, so this is even for Enterprise&lt;SPAN&gt;&amp;nbsp;Trial? I just registered and downloaded so i thought i would be able to use all the features.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"When you first download and install Splunk Enterprise,&lt;FONT color="#FF6600"&gt; an Enterprise Trial license&lt;/FONT&gt; is created and enabled by default. You can continue to use the Enterprise Trial license until it expires, or switch to the Free license right away depending on your requirements."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so i understand no alerts via email but also no alerts in Splunk alerts tab as well?&lt;/P&gt;&lt;P&gt;please read this comment ( after trail will end)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Pablo00_0-1650867605075.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19283i4607EC84660A41E6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Pablo00_0-1650867605075.png" alt="Pablo00_0-1650867605075.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 06:20:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595105#M13779</guid>
      <dc:creator>Pablo00</dc:creator>
      <dc:date>2022-04-25T06:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: why alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595139#M13781</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Unless you can send email from your server/workstations command line you must configure SMTP settings. You could found those on Settings -&amp;gt; Server Settings -&amp;gt; Email Settings. It's default is just use it's server's local email server (which you haven't in laptop/workstation and maybe not configured in your servers too).&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 09:11:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595139#M13781</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-04-25T09:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: why alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595145#M13782</link>
      <description>&lt;P&gt;Thank you!&lt;BR /&gt;&lt;BR /&gt;so email alerts are a bit advanced then. I will try to do it anyway (as I have access to azure cloud subscription)&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I am wondering why I am not able to see any alerts in web app? (when i go to search i am able to see events, so alert should be triggered?)&amp;nbsp;&lt;BR /&gt;many thanks&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Pablo00_0-1650878973022.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19290i61FB0AF67744994A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Pablo00_0-1650878973022.png" alt="Pablo00_0-1650878973022.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 09:30:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595145#M13782</guid>
      <dc:creator>Pablo00</dc:creator>
      <dc:date>2022-04-25T09:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: why alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595151#M13783</link>
      <description>&lt;P&gt;When you are using real-time alert (really you never need to use real-time alerts, those usually generates more issues than solves) it's fire only when there is coming a new events not for those which you have already indexed. I propose that you change this to "historic" alert where you define time slot from where you are looking those events and then add regular time when splunk has running it (cron or regularly one a hour/day etc.).&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 09:40:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595151#M13783</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-04-25T09:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: why alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595159#M13786</link>
      <description>&lt;P&gt;Thank you for your help. I understand that now!&lt;BR /&gt;&lt;BR /&gt;very much appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 09:52:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alerts-are-not-working/m-p/595159#M13786</guid>
      <dc:creator>Pablo00</dc:creator>
      <dc:date>2022-04-25T09:52:26Z</dc:date>
    </item>
  </channel>
</rss>

