<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set up alerts for high response time? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-set-up-alerts-for-high-response-time/m-p/159419#M2611</link>
    <description>&lt;P&gt;Check the EXPIRATION time of your alert.It may have been expired. &lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2015 15:12:46 GMT</pubDate>
    <dc:creator>stephane_cyrill</dc:creator>
    <dc:date>2015-04-28T15:12:46Z</dc:date>
    <item>
      <title>How to set up alerts for high response time?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-up-alerts-for-high-response-time/m-p/159418#M2610</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Current Alert Setup:&lt;/STRONG&gt;&lt;BR /&gt;
I am trying to set up an alert to send an email when the response time from the server is higher (&amp;gt;60ms). I have the webpage running on 4 hosts.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Search string:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=iserver env=prod sourcetype="iis-access"  uri_path="index.html" code=200 | where time_taken &amp;gt; 60
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Alert Type:&lt;/STRONG&gt; Real-time.&lt;BR /&gt;
&lt;STRONG&gt;Trigger Condition:&lt;/STRONG&gt; Number of Results is &amp;gt; 1 in 5 minutes. Edit&lt;BR /&gt;
&lt;STRONG&gt;When triggered, execute actions:&lt;/STRONG&gt;  For each result.&lt;/P&gt;

&lt;P&gt;I have a throttle setup for the field 'host' for 2 minutes.  I do not want the same host to be reported for next 2 minutes at least.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Problem:&lt;/STRONG&gt;  The alert triggers perfectly and shoots an email only once for each result after setup  and for the rest of the day, I do not get any email alerts.  But the search returns results when I open it in search in real-time.   &lt;/P&gt;

&lt;P&gt;Can someone help me identify where am I getting it wrong?  &lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 14:19:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-up-alerts-for-high-response-time/m-p/159418#M2610</guid>
      <dc:creator>pashernx</dc:creator>
      <dc:date>2015-04-28T14:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up alerts for high response time?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-up-alerts-for-high-response-time/m-p/159419#M2611</link>
      <description>&lt;P&gt;Check the EXPIRATION time of your alert.It may have been expired. &lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 15:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-up-alerts-for-high-response-time/m-p/159419#M2611</guid>
      <dc:creator>stephane_cyrill</dc:creator>
      <dc:date>2015-04-28T15:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up alerts for high response time?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-up-alerts-for-high-response-time/m-p/159420#M2612</link>
      <description>&lt;P&gt;I hope you are referring editing below parameter in &lt;STRONG&gt;$SPLUNK_BASE/etc/system/local/savedsearches.conf&lt;/STRONG&gt; file.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;alert.expires = &amp;lt;new_value&amp;gt;
# it was 24h in the defaults
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 27 Mar 2019 00:57:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-up-alerts-for-high-response-time/m-p/159420#M2612</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-03-27T00:57:45Z</dc:date>
    </item>
  </channel>
</rss>

