<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk alert trigger issue in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701844#M16213</link>
    <description>&lt;P&gt;and here i have tried the scheduled alert and here is the logs related to that alert:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;log 1:&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;10-14-2024&lt;/SPAN&gt; &lt;SPAN class=""&gt;22:16:01.088&lt;/SPAN&gt; +&lt;SPAN class=""&gt;0400&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;SavedSplunker&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;AlertNotifier::notifySearchCompleted:&lt;/SPAN&gt; &lt;SPAN class=""&gt;called&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;sid=scheduler__kareem__search__kareem_at_1728929760_35&lt;/SPAN&gt;, &lt;SPAN class=""&gt;condition=1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;log 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;10-14-2024&lt;/SPAN&gt; &lt;SPAN class=""&gt;22:16:01.809&lt;/SPAN&gt; +&lt;SPAN class=""&gt;0400&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;SavedSplunker&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;savedsearch_id=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;nobody&lt;/SPAN&gt;;&lt;SPAN class=""&gt;search&lt;/SPAN&gt;;&lt;SPAN class=""&gt;kareem&lt;/SPAN&gt;", &lt;SPAN class=""&gt;search_type=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;scheduled&lt;/SPAN&gt;", &lt;SPAN class=""&gt;search_streaming=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;user=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;kareem&lt;/SPAN&gt;", &lt;SPAN class=""&gt;app=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;search&lt;/SPAN&gt;", &lt;SPAN class=""&gt;savedsearch_name=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;kareem&lt;/SPAN&gt;", &lt;SPAN class=""&gt;priority=default&lt;/SPAN&gt;, &lt;SPAN class=""&gt;status=success&lt;/SPAN&gt;, &lt;SPAN class=""&gt;digest_mode=1&lt;/SPAN&gt;, &lt;SPAN class=""&gt;durable_cursor=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;scheduled_time=1728929760&lt;/SPAN&gt;, &lt;SPAN class=""&gt;window_time=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;dispatch_time=1728929760&lt;/SPAN&gt;, &lt;SPAN class=""&gt;run_time=0.178&lt;/SPAN&gt;, &lt;SPAN class=""&gt;result_count=1531&lt;/SPAN&gt;, &lt;SPAN class=""&gt;alert_actions=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;email&lt;/SPAN&gt;", &lt;SPAN class=""&gt;sid=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;scheduler__kareem__search__kareem_at_1728929760_35&lt;/SPAN&gt;", &lt;SPAN class=""&gt;suppressed=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;action_time_ms=718&lt;/SPAN&gt;, &lt;SPAN class=""&gt;thread_id=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;AlertNotifierWorker-0&lt;/SPAN&gt;", &lt;SPAN class=""&gt;workload_pool=&lt;/SPAN&gt;""&lt;/P&gt;</description>
    <pubDate>Mon, 14 Oct 2024 18:22:10 GMT</pubDate>
    <dc:creator>Kareem_Naeem</dc:creator>
    <dc:date>2024-10-14T18:22:10Z</dc:date>
    <item>
      <title>Splunk alert trigger issue</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701840#M16210</link>
      <description>&lt;P&gt;my alert is not triggered even with many matching events here are the details:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot from 2024-10-14 21-21-27.png" style="width: 944px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33084i42592421C67E8CD3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot from 2024-10-14 21-21-27.png" alt="Screenshot from 2024-10-14 21-21-27.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot from 2024-10-14 21-28-28.png" style="width: 508px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33087i656B582C0C9E12D1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot from 2024-10-14 21-28-28.png" alt="Screenshot from 2024-10-14 21-28-28.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;while the activity that generate these logs is running the real time alert is processing and found those events in the screenshot. i have waited for 5 mins and same issue&lt;/P&gt;&lt;P&gt;i have also tries scheduled and still the same issue no triggering&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 17:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701840#M16210</guid>
      <dc:creator>Kareem_Naeem</dc:creator>
      <dc:date>2024-10-14T17:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk alert trigger issue</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701841#M16211</link>
      <description>&lt;P&gt;1. Please, don't use real-time alerts. Except for very very rare cases real-time searches should be avoided altogether.&lt;/P&gt;&lt;P&gt;2. How did you confirm that the alerts weren't triggered? Is the email the only action you have defined? Maybe the problem is with your action, not the alert itself.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 17:43:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701841#M16211</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-10-14T17:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk alert trigger issue</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701842#M16212</link>
      <description>&lt;P&gt;email was the only action&amp;nbsp;&lt;/P&gt;&lt;P&gt;and how did i know is by checking the triggered alerts secion under activity, and as i said i tried scueduled alerts the same issue&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 17:51:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701842#M16212</guid>
      <dc:creator>Kareem_Naeem</dc:creator>
      <dc:date>2024-10-14T17:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk alert trigger issue</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701844#M16213</link>
      <description>&lt;P&gt;and here i have tried the scheduled alert and here is the logs related to that alert:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;log 1:&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;10-14-2024&lt;/SPAN&gt; &lt;SPAN class=""&gt;22:16:01.088&lt;/SPAN&gt; +&lt;SPAN class=""&gt;0400&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;SavedSplunker&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;AlertNotifier::notifySearchCompleted:&lt;/SPAN&gt; &lt;SPAN class=""&gt;called&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;sid=scheduler__kareem__search__kareem_at_1728929760_35&lt;/SPAN&gt;, &lt;SPAN class=""&gt;condition=1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;log 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;10-14-2024&lt;/SPAN&gt; &lt;SPAN class=""&gt;22:16:01.809&lt;/SPAN&gt; +&lt;SPAN class=""&gt;0400&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;SavedSplunker&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;savedsearch_id=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;nobody&lt;/SPAN&gt;;&lt;SPAN class=""&gt;search&lt;/SPAN&gt;;&lt;SPAN class=""&gt;kareem&lt;/SPAN&gt;", &lt;SPAN class=""&gt;search_type=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;scheduled&lt;/SPAN&gt;", &lt;SPAN class=""&gt;search_streaming=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;user=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;kareem&lt;/SPAN&gt;", &lt;SPAN class=""&gt;app=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;search&lt;/SPAN&gt;", &lt;SPAN class=""&gt;savedsearch_name=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;kareem&lt;/SPAN&gt;", &lt;SPAN class=""&gt;priority=default&lt;/SPAN&gt;, &lt;SPAN class=""&gt;status=success&lt;/SPAN&gt;, &lt;SPAN class=""&gt;digest_mode=1&lt;/SPAN&gt;, &lt;SPAN class=""&gt;durable_cursor=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;scheduled_time=1728929760&lt;/SPAN&gt;, &lt;SPAN class=""&gt;window_time=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;dispatch_time=1728929760&lt;/SPAN&gt;, &lt;SPAN class=""&gt;run_time=0.178&lt;/SPAN&gt;, &lt;SPAN class=""&gt;result_count=1531&lt;/SPAN&gt;, &lt;SPAN class=""&gt;alert_actions=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;email&lt;/SPAN&gt;", &lt;SPAN class=""&gt;sid=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;scheduler__kareem__search__kareem_at_1728929760_35&lt;/SPAN&gt;", &lt;SPAN class=""&gt;suppressed=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;action_time_ms=718&lt;/SPAN&gt;, &lt;SPAN class=""&gt;thread_id=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;AlertNotifierWorker-0&lt;/SPAN&gt;", &lt;SPAN class=""&gt;workload_pool=&lt;/SPAN&gt;""&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 18:22:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701844#M16213</guid>
      <dc:creator>Kareem_Naeem</dc:creator>
      <dc:date>2024-10-14T18:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk alert trigger issue</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701848#M16214</link>
      <description>&lt;P&gt;You must explicitly add an action to add an alert to triggered alerts. So if your only action was email, you must check why the email wasn't delivered (look in _internal for sendemail.py). At first glance your logs suggest that the alert notifier was actually dispatched.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 18:43:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/701848#M16214</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-10-14T18:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk alert trigger issue</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/702002#M16215</link>
      <description>&lt;P&gt;i have had an error in the email logs and i have fized it and now im receiving emails correctly in my local mail server but still the alert when triggered it's not shown in the triggered alerts&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 20:49:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-alert-trigger-issue/m-p/702002#M16215</guid>
      <dc:creator>Kareem_Naeem</dc:creator>
      <dc:date>2024-10-15T20:49:48Z</dc:date>
    </item>
  </channel>
</rss>

