<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloning and disabling rule causing problems- How to trigger alert? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Cloning-and-disabling-rule-causing-problems-How-to-trigger-alert/m-p/618651#M14458</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thank you for responding! I've just tried your query and found out that 2 weeks ago, a few alerts were not triggered and were "skipped" due to "The maximum disk usage quota for this user has been reached." which makes sense. This is the reason of why I disabled my (testing) cloned alerts, to liberate some disk usage quota from my user (not the best way to proceed, I now kn&lt;SPAN&gt;ow I just have to increment my user's quota). This was the first time I detected some alerts not trig&lt;/SPAN&gt;&lt;SPAN&gt;gering. However, the second instance when this happened, was today.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Today, there are no results coming out from the query you mentioned, and the only change I have done in the past 2 weeks ago, that could potentially affect the original alert, was as mentioned before, disabling the cloned alert. I have now deleted the cloned alert and I am hopefully waiting to see the original alert trigger.&lt;/P&gt;&lt;P&gt;Is there something more I can verify?&amp;nbsp;&lt;/P&gt;&lt;P&gt;SC of the original alert being lastly skipped:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="skipped_original_alert.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22188iFB0A6C8BE8700EC7/image-size/large?v=v2&amp;amp;px=999" role="button" title="skipped_original_alert.png" alt="skipped_original_alert.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;skipped_original_alert.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SC of the cloned alert being skipped:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="skipped_cloned_alert.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22186iFDABC604101CC371/image-size/large?v=v2&amp;amp;px=999" role="button" title="skipped_cloned_alert.png" alt="skipped_cloned_alert.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;skipped_cloned_alert.png&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW, I am using version&amp;nbsp;&lt;SPAN&gt;9.0.2208.3&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Oct 2022 21:48:28 GMT</pubDate>
    <dc:creator>fherrero</dc:creator>
    <dc:date>2022-10-27T21:48:28Z</dc:date>
    <item>
      <title>Cloning and disabling rule causing problems- How to trigger alert?</title>
      <link>https://community.splunk.com/t5/Alerting/Cloning-and-disabling-rule-causing-problems-How-to-trigger-alert/m-p/618619#M14456</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;I have a suspicion that following this order of events, has caused an alert not to trigger when due:&lt;/P&gt;
&lt;P&gt;1) I cloned the original alert for testing purposes&lt;/P&gt;
&lt;P&gt;2) The 2 alerts find the same result and function simultaneously&lt;/P&gt;
&lt;P&gt;3) I disabled the cloned alert&lt;/P&gt;
&lt;P&gt;4) Original alert not triggering (no email being sent, no events being logged on our alert index...) when Splunk search is being fulfilled. I repeated the search with the Splunk logic and results come back. I have no other explanation than the mentioned above.&lt;/P&gt;
&lt;P&gt;Has anyone seen this happen before?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 17:58:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cloning-and-disabling-rule-causing-problems-How-to-trigger-alert/m-p/618619#M14456</guid>
      <dc:creator>fherrero</dc:creator>
      <dc:date>2022-10-27T17:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cloning and disabling rule causing problems- How to trigger alert?</title>
      <link>https://community.splunk.com/t5/Alerting/Cloning-and-disabling-rule-causing-problems-How-to-trigger-alert/m-p/618623#M14457</link>
      <description>&lt;P&gt;Did you check the scheduler logs to see if the original alert search is firing and finding results (index=_internal sourcetype=scheduler savedsearch_name="yourOriginalAlertSearchNameHere")?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 18:07:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cloning-and-disabling-rule-causing-problems-How-to-trigger-alert/m-p/618623#M14457</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-10-27T18:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cloning and disabling rule causing problems- How to trigger alert?</title>
      <link>https://community.splunk.com/t5/Alerting/Cloning-and-disabling-rule-causing-problems-How-to-trigger-alert/m-p/618651#M14458</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thank you for responding! I've just tried your query and found out that 2 weeks ago, a few alerts were not triggered and were "skipped" due to "The maximum disk usage quota for this user has been reached." which makes sense. This is the reason of why I disabled my (testing) cloned alerts, to liberate some disk usage quota from my user (not the best way to proceed, I now kn&lt;SPAN&gt;ow I just have to increment my user's quota). This was the first time I detected some alerts not trig&lt;/SPAN&gt;&lt;SPAN&gt;gering. However, the second instance when this happened, was today.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Today, there are no results coming out from the query you mentioned, and the only change I have done in the past 2 weeks ago, that could potentially affect the original alert, was as mentioned before, disabling the cloned alert. I have now deleted the cloned alert and I am hopefully waiting to see the original alert trigger.&lt;/P&gt;&lt;P&gt;Is there something more I can verify?&amp;nbsp;&lt;/P&gt;&lt;P&gt;SC of the original alert being lastly skipped:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="skipped_original_alert.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22188iFB0A6C8BE8700EC7/image-size/large?v=v2&amp;amp;px=999" role="button" title="skipped_original_alert.png" alt="skipped_original_alert.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;skipped_original_alert.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SC of the cloned alert being skipped:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="skipped_cloned_alert.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22186iFDABC604101CC371/image-size/large?v=v2&amp;amp;px=999" role="button" title="skipped_cloned_alert.png" alt="skipped_cloned_alert.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;skipped_cloned_alert.png&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW, I am using version&amp;nbsp;&lt;SPAN&gt;9.0.2208.3&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 21:48:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cloning-and-disabling-rule-causing-problems-How-to-trigger-alert/m-p/618651#M14458</guid>
      <dc:creator>fherrero</dc:creator>
      <dc:date>2022-10-27T21:48:28Z</dc:date>
    </item>
  </channel>
</rss>

