<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ghost alert in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Ghost-alert/m-p/30265#M292</link>
    <description>&lt;P&gt;How did you manually schedule the search? From the manager GUI or from the search itself?&lt;/P&gt;

&lt;P&gt;It might be that one search is per user and the other is per app or system.&lt;/P&gt;

&lt;P&gt;If you are using a linux box, then you can probably find it in the $SPLUNK_HOME/etc/ directory using something like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# find . -name savedsearches.conf |grep -i &amp;lt;savedSearchName&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 10 May 2013 19:26:22 GMT</pubDate>
    <dc:creator>Rob</dc:creator>
    <dc:date>2013-05-10T19:26:22Z</dc:date>
    <item>
      <title>Ghost alert</title>
      <link>https://community.splunk.com/t5/Alerting/Ghost-alert/m-p/30264#M291</link>
      <description>&lt;P&gt;Has anyone else seen an alert go out when it was not scheduled?  I manually scheduled an alert to go out for testing, say 11:15am.  Once verified, I scheduled that alert to go out at a specific time (8am, daily.)  However, now I'm getting 2 alerts, one for my scheduled time  (8am) and again at 11:15am.  &lt;/P&gt;

&lt;P&gt;In particular this was a scheduled PDF report.  I have not seen it happen with a non-PDF Report scheduled alert.&lt;/P&gt;

&lt;P&gt;The search was created in UI and scheduled from UI.  I scheduled a cron to run at 11:15am to verify that it worked.  Then I changed the schedule to ( 0 8 * * * ).  It has been running for several days now but I'm getting 2 alerts daily:  1 at 8:15am and another at 11:15am.&lt;/P&gt;

&lt;P&gt;I've scoured the filesystem and can find no evidence of where the ghost alert is coming from.  The search exists in savedsearches.conf with the ( 0 8 * * * ) schedule.  &lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2013 18:47:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Ghost-alert/m-p/30264#M291</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2013-05-10T18:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Ghost alert</title>
      <link>https://community.splunk.com/t5/Alerting/Ghost-alert/m-p/30265#M292</link>
      <description>&lt;P&gt;How did you manually schedule the search? From the manager GUI or from the search itself?&lt;/P&gt;

&lt;P&gt;It might be that one search is per user and the other is per app or system.&lt;/P&gt;

&lt;P&gt;If you are using a linux box, then you can probably find it in the $SPLUNK_HOME/etc/ directory using something like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# find . -name savedsearches.conf |grep -i &amp;lt;savedSearchName&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 10 May 2013 19:26:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Ghost-alert/m-p/30265#M292</guid>
      <dc:creator>Rob</dc:creator>
      <dc:date>2013-05-10T19:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ghost alert</title>
      <link>https://community.splunk.com/t5/Alerting/Ghost-alert/m-p/30266#M293</link>
      <description>&lt;P&gt;The issue was resolved by restarting the SHs (we're using a pool).  This appears to be some sort of bug (version 4.3.4).&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2013 17:21:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Ghost-alert/m-p/30266#M293</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2013-05-21T17:21:07Z</dc:date>
    </item>
  </channel>
</rss>

