<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic help on Splunk alert recurrence in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668439#M15496</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I use a splunk alert with a 24 hours slottime&lt;/P&gt;&lt;P&gt;what is strange is that this alert show me an event older than 24 hours&lt;/P&gt;&lt;P&gt;so I have 2 questiosn&lt;/P&gt;&lt;P&gt;1) How is it possible that an alert occurs with an event outside the slot time specified?&lt;/P&gt;&lt;P&gt;2) How to customize the alert for being sure that it shows only new events and not events already shown?&amp;nbsp;&lt;/P&gt;&lt;P&gt;It means that I need the alert occurs just one time when an event is detected&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Mon, 13 Nov 2023 15:37:35 GMT</pubDate>
    <dc:creator>jip31</dc:creator>
    <dc:date>2023-11-13T15:37:35Z</dc:date>
    <item>
      <title>help on Splunk alert recurrence</title>
      <link>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668439#M15496</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I use a splunk alert with a 24 hours slottime&lt;/P&gt;&lt;P&gt;what is strange is that this alert show me an event older than 24 hours&lt;/P&gt;&lt;P&gt;so I have 2 questiosn&lt;/P&gt;&lt;P&gt;1) How is it possible that an alert occurs with an event outside the slot time specified?&lt;/P&gt;&lt;P&gt;2) How to customize the alert for being sure that it shows only new events and not events already shown?&amp;nbsp;&lt;/P&gt;&lt;P&gt;It means that I need the alert occurs just one time when an event is detected&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 15:37:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668439#M15496</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2023-11-13T15:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: help on Splunk alert recurrence</title>
      <link>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668441#M15497</link>
      <description>&lt;P&gt;Your search has to be able to filter out the events you don't want, or have already looked at. This will depend&amp;nbsp;on your search and your data.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 15:51:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668441#M15497</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-13T15:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: help on Splunk alert recurrence</title>
      <link>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668442#M15498</link>
      <description>&lt;P&gt;Have you an example to filter events that&amp;nbsp;&lt;SPAN&gt;have already looked at? Is there any alert customization for doing that like throttle or expiration?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 15:53:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668442#M15498</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2023-11-13T15:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: help on Splunk alert recurrence</title>
      <link>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668445#M15499</link>
      <description>&lt;P&gt;Alerts have throttles but that's at the alert level, not at the event which have been looked at.&lt;/P&gt;&lt;P&gt;As I said, it depends on your search and your data. For example, if you are searching over 25 hours, every 24 hours, there will be an overlap of 1 hour. Having said that, it depends how quickly your data is indexed, real lag, and how far behind your timestamp field (_time) is to actual time, extended lag. In order to fashion a search which takes these factors into account, you need to understand your data, how it is indexed, when it is indexed, etc. When you know this, you might have a chance at eliminating events which you have (or may have) already looked at.&lt;/P&gt;&lt;P&gt;Another way you might approach this is to copy the events you have looked at into a summary index and then ignore any events which are already in your summary index.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 16:00:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668445#M15499</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-13T16:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: help on Splunk alert recurrence</title>
      <link>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668448#M15501</link>
      <description>&lt;P&gt;thanks for your answer even if it's not really easy to understand&lt;/P&gt;&lt;P&gt;the data are approximatively indexed every 20 minutes&lt;/P&gt;&lt;P&gt;so concerning my problem i dont understand why my last related event vs my alert happened last Friday and why my alert has occurend once again today&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 16:29:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668448#M15501</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2023-11-13T16:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: help on Splunk alert recurrence</title>
      <link>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668450#M15502</link>
      <description>&lt;P&gt;You haven't provided sufficient information for anyone to be able to determine why your search picked up events which you weren't expecting, or why you search failed to exclude these from your alert. It is like me asking you, why did my search fail?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 16:35:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/help-on-Splunk-alert-recurrence/m-p/668450#M15502</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-13T16:35:59Z</dc:date>
    </item>
  </channel>
</rss>

