<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limit number of alerts in RSS in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27585#M241</link>
    <description>&lt;P&gt;Never really tried this, as it seems to me the items_count affects the RSS feeds of all alerts, not just this specific one.&lt;/P&gt;</description>
    <pubDate>Sun, 01 Feb 2015 11:09:42 GMT</pubDate>
    <dc:creator>echalex</dc:creator>
    <dc:date>2015-02-01T11:09:42Z</dc:date>
    <item>
      <title>Limit number of alerts in RSS</title>
      <link>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27581#M237</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm using an RSS feed to view alerts from a scheduled search. The purpose is to maintain a sort of dead man's grip monitoring that feed with a third party application. The RSS feed does not need authentication, which is why I prefer this over the RESTful API.&lt;/P&gt;

&lt;P&gt;However, the RSS keeps track of the 30 latest alerts, even after they have expired. Is there a way not showing expired alert or limiting the number of alerts in the RSS feed?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2012 13:07:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27581#M237</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2012-08-07T13:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Limit number of alerts in RSS</title>
      <link>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27582#M238</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am not sure but I feel that once a search gets expired, the corresponding search results directory in "dispatch" folder also gets deleted.&lt;/P&gt;

&lt;P&gt;If that's true, whenever you fetch RSS feed, you can extract the sub folder inside dispatch directory to see if it exists or not and if it does not exists, you can stop processing more on the RSS entry just fetched.&lt;/P&gt;

&lt;P&gt;Let me know your views and if it helps.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Amit Saxena&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2013 17:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27582#M238</guid>
      <dc:creator>amit_saxena</dc:creator>
      <dc:date>2013-09-12T17:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Limit number of alerts in RSS</title>
      <link>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27583#M239</link>
      <description>&lt;P&gt;UP&lt;/P&gt;

&lt;P&gt;I tried to setup &lt;BR /&gt;
&lt;CODE&gt;items_count=1&lt;/CODE&gt;&lt;BR /&gt;
in alert_actions.conf under [rss] stanza, as specified in .spec file,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;items_count = &amp;lt;number&amp;gt;
    * Number of saved RSS feeds.
    * Cannot be more than maxresults (in the global settings).
    * Defaults to 30.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but I still found 30 items.&lt;/P&gt;

&lt;P&gt;Any hint?&lt;/P&gt;

&lt;P&gt;Ciao&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2014 12:49:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27583#M239</guid>
      <dc:creator>bizza</dc:creator>
      <dc:date>2014-10-23T12:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Limit number of alerts in RSS</title>
      <link>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27584#M240</link>
      <description>&lt;P&gt;To be honest, I never tried this solution. This apparently requires shell access to the dispatch directory. Therefore it is not exactly in line with what I want to achieve.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Feb 2015 11:04:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27584#M240</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2015-02-01T11:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Limit number of alerts in RSS</title>
      <link>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27585#M241</link>
      <description>&lt;P&gt;Never really tried this, as it seems to me the items_count affects the RSS feeds of all alerts, not just this specific one.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Feb 2015 11:09:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Limit-number-of-alerts-in-RSS/m-p/27585#M241</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2015-02-01T11:09:42Z</dc:date>
    </item>
  </channel>
</rss>

