<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help in setting alert in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202040#M3518</link>
    <description>&lt;P&gt;its not every 5 minutes,it will alert if the count is greater than 50 in a 5  mins window&lt;/P&gt;</description>
    <pubDate>Thu, 14 Apr 2016 17:05:24 GMT</pubDate>
    <dc:creator>vrmandadi</dc:creator>
    <dc:date>2016-04-14T17:05:24Z</dc:date>
    <item>
      <title>Help in setting alert</title>
      <link>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202038#M3516</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am setting an alert based on the count i.e if the count is greater than 50 then we need to generate an alert.&lt;/P&gt;

&lt;P&gt;I wrote the query and saved as alert&lt;/P&gt;

&lt;P&gt;alert type=Real time&lt;BR /&gt;
Trigger Condition=Custom&lt;BR /&gt;
Custom Condition= search count&amp;gt;50&lt;BR /&gt;
time: in 5 mins&lt;BR /&gt;
 and then selected the e-mail as triggered condition&lt;/P&gt;

&lt;P&gt;in Throttle what should I give such that the alert when generated in 5 minutes  should set the time back to zero before generating another alert&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 22:53:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202038#M3516</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2016-04-13T22:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Help in setting alert</title>
      <link>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202039#M3517</link>
      <description>&lt;P&gt;If your search is scheduled to run every five minutes (is it, actually?), then set the throttling to suppress the alert to something greater than five minutes. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 23:22:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202039#M3517</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-04-13T23:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: Help in setting alert</title>
      <link>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202040#M3518</link>
      <description>&lt;P&gt;its not every 5 minutes,it will alert if the count is greater than 50 in a 5  mins window&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 17:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202040#M3518</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2016-04-14T17:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Help in setting alert</title>
      <link>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202041#M3519</link>
      <description>&lt;P&gt;So what is the schedule you have set for the search itself?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 17:11:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202041#M3519</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-04-14T17:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Help in setting alert</title>
      <link>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202042#M3520</link>
      <description>&lt;P&gt;all time for search,the alert is customized &lt;/P&gt;

&lt;P&gt;search count&amp;gt;50 &lt;/P&gt;

&lt;P&gt;is the syntax correct for the alert or should it be in double quotes&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 21:26:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202042#M3520</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2016-04-14T21:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Help in setting alert</title>
      <link>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202043#M3521</link>
      <description>&lt;P&gt;Hi @vrmandadi,&lt;BR /&gt;
I think it might be helpful to reconsider the alerting behavior you would like to have. When you say, "set the time back to zero" in your original question, it makes me think that you might want a scheduled alert that runs a search every five minutes to check for more than 50 events. If there are more than 50 results for that search, you get an email notification. Does that sound more like the outcome you are trying to set up? Let me know either way and I can suggest some resources.&lt;/P&gt;

&lt;P&gt;As a start, this comparison chart might help.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Alert/AlertTypesOverview"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Alert/AlertTypesOverview&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 22:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Help-in-setting-alert/m-p/202043#M3521</guid>
      <dc:creator>frobinson_splun</dc:creator>
      <dc:date>2016-04-14T22:24:52Z</dc:date>
    </item>
  </channel>
</rss>

