<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring Alerts in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Configuring-Alerts/m-p/106833#M1533</link>
    <description>&lt;P&gt;Set up the search to run every five minutes, with the time interval as:&lt;/P&gt;

&lt;P&gt;Start time: -5m@m     Finish time: now&lt;/P&gt;

&lt;P&gt;Next, Set "Alert mode" to "Once per result" to get a separate alert per result found rather than a single alert for the whole search across the 5 minutes.&lt;/P&gt;

&lt;P&gt;Just be sure to set it up to send email and you are set.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jul 2013 04:05:19 GMT</pubDate>
    <dc:creator>jtrucks</dc:creator>
    <dc:date>2013-07-26T04:05:19Z</dc:date>
    <item>
      <title>Configuring Alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Configuring-Alerts/m-p/106832#M1532</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have been using splunk as a syslog server for a while now and have around 8 - 10 alerts tat I have created.  I have recently had issues with creating any additional alerts and have pretty much determined that it is because I have hit a limit on how many real time alerts I have setup.&lt;/P&gt;

&lt;P&gt;I am now going through all my alerts to see which ones I don't need to have real time alerting on.  My question is this.  I want to perform a search every 5 minutes...if a search comes up with a specific search string within that 5 minutes, I would like it to alert once for every time it is found.&lt;/P&gt;

&lt;P&gt;Is this achieved just by setting up a basic schedule as well as setting the time range?  And would I do something like having the start time at -5m and the finish time to now?&lt;/P&gt;

&lt;P&gt;Thanks for your help....&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2013 20:40:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Configuring-Alerts/m-p/106832#M1532</guid>
      <dc:creator>MichaelBernas</dc:creator>
      <dc:date>2013-07-25T20:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Configuring-Alerts/m-p/106833#M1533</link>
      <description>&lt;P&gt;Set up the search to run every five minutes, with the time interval as:&lt;/P&gt;

&lt;P&gt;Start time: -5m@m     Finish time: now&lt;/P&gt;

&lt;P&gt;Next, Set "Alert mode" to "Once per result" to get a separate alert per result found rather than a single alert for the whole search across the 5 minutes.&lt;/P&gt;

&lt;P&gt;Just be sure to set it up to send email and you are set.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2013 04:05:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Configuring-Alerts/m-p/106833#M1533</guid>
      <dc:creator>jtrucks</dc:creator>
      <dc:date>2013-07-26T04:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Configuring-Alerts/m-p/106834#M1534</link>
      <description>&lt;P&gt;Thanks jtrucks,&lt;/P&gt;

&lt;P&gt;I had set the start time to -5m.  What is the difference between what I set and -5m@m.&lt;/P&gt;

&lt;P&gt;I appreciate the help!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2013 14:47:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Configuring-Alerts/m-p/106834#M1534</guid>
      <dc:creator>MichaelBernas</dc:creator>
      <dc:date>2013-07-26T14:47:40Z</dc:date>
    </item>
  </channel>
</rss>

