<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alerts problem on 6.1.1 in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alerts-problem-on-6-1-1/m-p/185143#M3096</link>
    <description>&lt;P&gt;Since I upgraded SPLUNK to 6.1, I have a problem with my alerts.&lt;BR /&gt;
After few hours they stop working. I must restart SPLUNK and my alerts are back to work until they stop working.&lt;BR /&gt;
How can I resolve that ?&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jun 2014 11:53:45 GMT</pubDate>
    <dc:creator>macewindum</dc:creator>
    <dc:date>2014-06-02T11:53:45Z</dc:date>
    <item>
      <title>Alerts problem on 6.1.1</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-problem-on-6-1-1/m-p/185143#M3096</link>
      <description>&lt;P&gt;Since I upgraded SPLUNK to 6.1, I have a problem with my alerts.&lt;BR /&gt;
After few hours they stop working. I must restart SPLUNK and my alerts are back to work until they stop working.&lt;BR /&gt;
How can I resolve that ?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 11:53:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-problem-on-6-1-1/m-p/185143#M3096</guid>
      <dc:creator>macewindum</dc:creator>
      <dc:date>2014-06-02T11:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts problem on 6.1.1</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-problem-on-6-1-1/m-p/185144#M3097</link>
      <description>&lt;P&gt;Ran into this over the weekend myself. It looks to be known issue SPL-84357&lt;/P&gt;

&lt;P&gt;The response I found at &lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/137421/why-are-my-real-time-alerting-searches-no-longer-sending-emails-for-matching-events-after-upgrading-to-61"&gt;http://answers.splunk.com/answers/137421/why-are-my-real-time-alerting-searches-no-longer-sending-emails-for-matching-events-after-upgrading-to-61&lt;/A&gt;&lt;BR /&gt;
provided the following workaround:&lt;/P&gt;

&lt;P&gt;The work-around is to temporarily extend "sessionTimeout" in $SPLUNK_HOME/etc/system/local/server.conf to a value that will be longer than the interval between two matched events, thus preventing the token from expiring:&lt;BR /&gt;
[general]&lt;BR /&gt;
sessionTimeout = 30d&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 12:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-problem-on-6-1-1/m-p/185144#M3097</guid>
      <dc:creator>mtranchita</dc:creator>
      <dc:date>2014-06-02T12:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts problem on 6.1.1</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-problem-on-6-1-1/m-p/185145#M3098</link>
      <description>&lt;P&gt;Thanks for the answer.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 12:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-problem-on-6-1-1/m-p/185145#M3098</guid>
      <dc:creator>macewindum</dc:creator>
      <dc:date>2014-06-02T12:29:56Z</dc:date>
    </item>
  </channel>
</rss>

