<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert Condition and Indexer in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-Condition-and-Indexer/m-p/105571#M1508</link>
    <description>&lt;P&gt;I've added missing infos in question&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jul 2012 07:59:02 GMT</pubDate>
    <dc:creator>rzessin</dc:creator>
    <dc:date>2012-07-24T07:59:02Z</dc:date>
    <item>
      <title>Alert Condition and Indexer</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Condition-and-Indexer/m-p/105569#M1506</link>
      <description>&lt;P&gt;I have a saved search which triggeres if there are are less than 2 items within an hour.&lt;BR /&gt;
Sometimes the Trigger happens but the condition wasn't true. The file contains the items,&lt;BR /&gt;
but the indexer has not made the work for hours, last time it was true for 17 hours.&lt;/P&gt;

&lt;P&gt;I've nothing found in logs, maybe I've looked in wrong place, is there any chance to see if indexex get stucks to see on which file ?&lt;/P&gt;

&lt;P&gt;Definition of scheduled Search:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;BR /&gt;&lt;BR /&gt;
[CRL-Copy]&lt;BR /&gt;
action.email = 1&lt;BR /&gt;
action.email.inline = 1&lt;BR /&gt;
action.email.sendresults = 1&lt;BR /&gt;
action.email.subject = [Splunk Alert: $name$]&lt;BR /&gt;
action.email.to = &lt;REMOVED&gt;&lt;BR /&gt;
alert.suppress = 0&lt;BR /&gt;
alert.track = 1&lt;BR /&gt;
counttype = number of events&lt;BR /&gt;
cron_schedule = */30 * * * *&lt;BR /&gt;
dispatch.earliest_time = -60m&lt;BR /&gt;
dispatch.latest_time = now&lt;BR /&gt;
displayview = flashtimeline&lt;BR /&gt;
enableSched = 1&lt;BR /&gt;
quantity = 2&lt;BR /&gt;
relation = less than&lt;BR /&gt;
request.ui_dispatch_view = flashtimeline&lt;BR /&gt;
search = CRL-copy sourcetype="syslog-ng-modified" host="&lt;EDITED&gt;" ok&lt;BR /&gt;
&lt;/EDITED&gt;&lt;/REMOVED&gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;The intention is if the Certificate Revocation List isn't published at least one time in past hour an alert has t be sent. The CRL-Copy-Task itselfs run each 15 minutes via cron&lt;/P&gt;

&lt;P&gt;And if i doing the search now I see for each hour bound to quarter the four entries which is telling me that the indexer has got stuck.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:07:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Condition-and-Indexer/m-p/105569#M1506</guid>
      <dc:creator>rzessin</dc:creator>
      <dc:date>2020-09-28T12:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Condition and Indexer</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Condition-and-Indexer/m-p/105570#M1507</link>
      <description>&lt;P&gt;What are the search that you used to alert, the condition and the schedule ?&lt;/P&gt;

&lt;P&gt;Were the events searchable in splunk, with the correct timestamp ?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2012 18:16:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Condition-and-Indexer/m-p/105570#M1507</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-07-23T18:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Condition and Indexer</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Condition-and-Indexer/m-p/105571#M1508</link>
      <description>&lt;P&gt;I've added missing infos in question&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2012 07:59:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Condition-and-Indexer/m-p/105571#M1508</guid>
      <dc:creator>rzessin</dc:creator>
      <dc:date>2012-07-24T07:59:02Z</dc:date>
    </item>
  </channel>
</rss>

