<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is my simple alert not firing? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353498#M6260</link>
    <description>&lt;P&gt;I have looked into the Splunk Monitoring Console and the Alerts section shows 0 alerts triggered.&lt;/P&gt;

&lt;P&gt;I have the search running every 5 mins just incase there is an issue with the every minute search.&lt;/P&gt;

&lt;P&gt;I still see 0 alerts.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Mar 2017 12:54:05 GMT</pubDate>
    <dc:creator>nfspeedypur</dc:creator>
    <dc:date>2017-03-14T12:54:05Z</dc:date>
    <item>
      <title>Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353487#M6249</link>
      <description>&lt;P&gt;I have a simple scheduled search that is running every 5 minute.  The search runs fine and I can see there are results, normally between 10-20 results.  The alert trigger is set to 'Trigger Condition: Number of Results is &amp;gt; 1'  However I never get an alert trigger to occur.&lt;/P&gt;

&lt;P&gt;I have checked the Splunk logs and the scheduler has 100% successful runs.  I am not sure what could be the reason for this not sending an alert.&lt;/P&gt;

&lt;P&gt;Trial expires in May.&lt;/P&gt;

&lt;P&gt;-David&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 20:39:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353487#M6249</guid>
      <dc:creator>nfspeedypur</dc:creator>
      <dc:date>2017-03-13T20:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353488#M6250</link>
      <description>&lt;P&gt;How do you know it is not triggering?  Is it here?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rest/servicesNS/-/-/alerts/fired_alerts
| search NOT title="-"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 13 Mar 2017 21:23:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353488#M6250</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-03-13T21:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353489#M6251</link>
      <description>&lt;P&gt;What is the alert search query?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 21:25:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353489#M6251</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-03-13T21:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353490#M6252</link>
      <description>&lt;P&gt;That returns 0 results.  I see recent activity showing the searches and results.  Then I see 0 alerts in the 'searches, reports, and alerts' for the 1 search.  In addition the alert was set to trigger an email, which it is not doing.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 21:30:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353490#M6252</guid>
      <dc:creator>nfspeedypur</dc:creator>
      <dc:date>2017-03-13T21:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353491#M6253</link>
      <description>&lt;P&gt;When you look at the saved search and "recent runs", do they show any results?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 21:32:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353491#M6253</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-03-13T21:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353492#M6254</link>
      <description>&lt;P&gt;source="Perfmon*" counter="% Free Space" Value&amp;lt;60&lt;/P&gt;

&lt;P&gt;Condition - If Number of Events - is greater than - 1&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 21:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353492#M6254</guid>
      <dc:creator>nfspeedypur</dc:creator>
      <dc:date>2017-03-13T21:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353493#M6255</link>
      <description>&lt;P&gt;I see a run every minute, for the past 2 hours, with over 20 items each.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 21:37:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353493#M6255</guid>
      <dc:creator>nfspeedypur</dc:creator>
      <dc:date>2017-03-13T21:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353494#M6256</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2611iCDD63A10D4605FA3/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2612iF97D4C19B3318798/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;These are screen caps of the recent runs and the settings&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 21:43:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353494#M6256</guid>
      <dc:creator>nfspeedypur</dc:creator>
      <dc:date>2017-03-13T21:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353495#M6257</link>
      <description>&lt;P&gt;Why "greater than" &lt;CODE&gt;1&lt;/CODE&gt;?  It should be &lt;CODE&gt;0&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 22:11:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353495#M6257</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-03-13T22:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353496#M6258</link>
      <description>&lt;P&gt;What is the lag time between when an event is created and when it is indexed?&lt;/P&gt;

&lt;P&gt;Consider this example: On a production server, an application writes to abc.log at 8:59:59. The Splunk forwarder sees that abc.log has been modified and collects the data, sending it to the indexer. The data is parsed and written to the main index at 9:00:03 - a 3 second delay (which is pretty quick).&lt;/P&gt;

&lt;P&gt;In the meantime, a search is running on the indexer every minute, searching the prior minute's data. Here is a table of the recent executions:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Search runs at:   Start Time:   End Time:
8:59:00             8:58:00      8:59:00
9:00:00             8:59:00      9:00:00
9:01:00             9:00:00      9:01:00
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When the search runs at 8:59:00, the event has not yet happened.&lt;BR /&gt;
When the search runs at 9:00:00, the event from abc.log has not yet been indexed, so it does not appear in the results.&lt;BR /&gt;
When the search runs at 9:01:00, the event from abc.log exists in the main index, but its timestamp is 8:59:59 - so it is outside the time range of the search! The event will not be part of any search results, so the alert will not be triggered.&lt;/P&gt;

&lt;P&gt;While I still think that something &lt;EM&gt;else&lt;/EM&gt; may be going wrong with your searches, you will alway risk "missing" events when you do not consider the lag time between when an event occurs on a machine and when the information is indexed. You have 2 choices:&lt;/P&gt;

&lt;P&gt;1 - Run a realtime search. This can be quite expensive, but you will not miss events.&lt;/P&gt;

&lt;P&gt;2 - Run a scheduled search, but include a lag time. To include a 1-minute lag, your search could be&lt;BR /&gt;
     Your search time range:  &lt;CODE&gt;earliest=-2m@m latest=-1m@m&lt;/CODE&gt; (starting 2 minutes ago, and ending 1 minute ago)&lt;BR /&gt;
     Cron schedule: &lt;CODE&gt;*/1 * * * *&lt;/CODE&gt;  (run every minute)&lt;BR /&gt;
     This works if there is less than a 1 minute delay between when the events occur and when they are indexed.&lt;/P&gt;

&lt;P&gt;Finally, you might want to look at the Splunk Monitoring Console. There is a dashboard for examining scheduled search activity. You may find that not all of your scheduled searches are being run, or that there are other problems in the environment.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 06:58:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353496#M6258</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2017-03-14T06:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353497#M6259</link>
      <description>&lt;P&gt;Right now my earliest - 1h.  The run time of every minute was to make the system run more often just to get the test completed faster.  I have changed this schedule to every 5 mins and every 15 mins but it is still not firing.&lt;/P&gt;

&lt;P&gt;I will take a look at the Splunk Monitoring Console.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 12:29:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353497#M6259</guid>
      <dc:creator>nfspeedypur</dc:creator>
      <dc:date>2017-03-14T12:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353498#M6260</link>
      <description>&lt;P&gt;I have looked into the Splunk Monitoring Console and the Alerts section shows 0 alerts triggered.&lt;/P&gt;

&lt;P&gt;I have the search running every 5 mins just incase there is an issue with the every minute search.&lt;/P&gt;

&lt;P&gt;I still see 0 alerts.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 12:54:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353498#M6260</guid>
      <dc:creator>nfspeedypur</dc:creator>
      <dc:date>2017-03-14T12:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353499#M6261</link>
      <description>&lt;P&gt;I believe you are on the right track, that things are not set up correctly.  I added an additional, none email alert, and that is working.  I believe the issue now is related to the Email service, not Splunk.  Thank you for the help in troubleshooting.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 13:16:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353499#M6261</guid>
      <dc:creator>nfspeedypur</dc:creator>
      <dc:date>2017-03-14T13:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my simple alert not firing?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353500#M6262</link>
      <description>&lt;P&gt;It may just be you need an explicit "field" statement at the end.&lt;/P&gt;

&lt;P&gt;See:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/686813/why-is-my-alert-not-triggering.html?childToView=752021#answer-752021"&gt;https://answers.splunk.com/answers/686813/why-is-my-alert-not-triggering.html?childToView=752021#answer-752021&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 21:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-my-simple-alert-not-firing/m-p/353500#M6262</guid>
      <dc:creator>templets</dc:creator>
      <dc:date>2019-06-12T21:28:03Z</dc:date>
    </item>
  </channel>
</rss>

