<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert triggering in Splunk due to slowness in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358591#M6323</link>
    <description>&lt;P&gt;Can you show what search is the base for the alert?&lt;/P&gt;</description>
    <pubDate>Mon, 19 Mar 2018 11:05:48 GMT</pubDate>
    <dc:creator>tiagofbmm</dc:creator>
    <dc:date>2018-03-19T11:05:48Z</dc:date>
    <item>
      <title>Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358590#M6322</link>
      <description>&lt;P&gt;we are alert in Splunk but when i checked, there is no issue.&lt;BR /&gt;
as Splunk long time to search to query may be the reason.&lt;BR /&gt;
Could anyone please give the suggestion &lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 10:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358590#M6322</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-19T10:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358591#M6323</link>
      <description>&lt;P&gt;Can you show what search is the base for the alert?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 11:05:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358591#M6323</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-03-19T11:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358592#M6324</link>
      <description>&lt;P&gt;actually its log event..&lt;BR /&gt;
index=index_days sourcetype=sourcetype_name "search sring" | stats count&lt;/P&gt;

&lt;P&gt;it will trigger alert if table value less than 1&lt;BR /&gt;
but it triggering when there is no issue&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:32:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358592#M6324</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2020-09-29T18:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358593#M6325</link>
      <description>&lt;P&gt;waiting for the someone to provide the update&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 11:55:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358593#M6325</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-19T11:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358594#M6326</link>
      <description>&lt;P&gt;@logloganathan are you using any custom alert condition or are you using condition if number of results &amp;gt; 1? &lt;BR /&gt;
 Also, have you kept any throttling for the alert and do you want it to trigger it only once or for each result.&lt;/P&gt;

&lt;P&gt;Let me know.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 12:25:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358594#M6326</guid>
      <dc:creator>abhijit_mhatre</dc:creator>
      <dc:date>2018-03-19T12:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358595#M6327</link>
      <description>&lt;P&gt;What do you mean by "it will trigger alert if table value less than 1"? Did you mean count  &amp;lt; 1 in your search?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 12:48:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358595#M6327</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-03-19T12:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358596#M6328</link>
      <description>&lt;P&gt;if number of results &amp;gt; 1 then only once &lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 13:40:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358596#M6328</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-19T13:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358597#M6329</link>
      <description>&lt;P&gt;table query display lot of row&lt;BR /&gt;
if it display no rows then i need alert&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 13:45:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358597#M6329</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-19T13:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358598#M6330</link>
      <description>&lt;P&gt;What's the time window the search is using? Depending on the delay for data populating through the system, a window that is too short/recent might alert even though data is in the index pipeline and shows up in later searches for the same time window.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 14:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358598#M6330</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2018-03-19T14:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358599#M6331</link>
      <description>&lt;P&gt;i am using last 60 minutes&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 15:01:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358599#M6331</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-19T15:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358600#M6332</link>
      <description>&lt;P&gt;Ah, then that's not likely the issue. Is the search alerting every time it runs, or just sometimes? If it's every time, maybe the search is running with the wrong permissions or in the wrong app to actually gather the data expected. &lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 15:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358600#M6332</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2018-03-19T15:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358601#M6333</link>
      <description>&lt;P&gt;search not altering everytime&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 15:41:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358601#M6333</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-19T15:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358602#M6334</link>
      <description>&lt;P&gt;waiting for the response.&lt;BR /&gt;
Could anyone please update&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 16:05:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358602#M6334</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-19T16:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358603#M6335</link>
      <description>&lt;P&gt;If the search is failing to alert every single time, have you done the troubleshooting step of manually running the specific search as the user who is scheduled to run the alert inside the same app? I've made the mistake before of building an alert in one app and then saving/scheduling it in another and discovering it wasn't able to run as expected.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 16:28:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358603#M6335</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2018-03-19T16:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358604#M6336</link>
      <description>&lt;P&gt;Can you tell us more about what you mean by "false alert is coming that is the issue due to slowness"? Are you saying your search takes so long to return that it times out, giving the false impression that there were no results? If so, maybe a solution would be to tune the query to ensure it never times out. &lt;/P&gt;

&lt;P&gt;Based on your comments above, it seems like you're running this query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=index_days sourcetype=sourcetype_name "search sring" | stats count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And you want it to alert if there are 0 results returned, right? But you are getting alerts for times when you think it should have found results? If so, maybe try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=index_days sourcetype=sourcetype_name "search sring" | head 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That way, if there's a single result, it will find the first one and return immediately. That could help with a timeout.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 12:25:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358604#M6336</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2018-03-20T12:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358605#M6337</link>
      <description>&lt;P&gt;wow exactly..same thing i want...Please enter the same in answer box&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 12:51:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358605#M6337</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-20T12:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358606#M6338</link>
      <description>&lt;P&gt;thanks for the answer&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 15:51:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358606#M6338</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-20T15:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358607#M6339</link>
      <description>&lt;P&gt;Could you please convert the same command to transforming command&lt;/P&gt;

&lt;P&gt;index=index_days sourcetype=sourcetype_name "search sring" | head 1&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:36:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358607#M6339</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2020-09-29T18:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358608#M6340</link>
      <description>&lt;P&gt;Sure, but what's the goal of doing so? If we're just transforming for the sake of turning it into a table:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=index_days sourcetype=sourcetype_name "search sring" 
| head 1
| stats values(*) AS *
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or&lt;BR /&gt;
    index=index_days sourcetype=sourcetype_name "search sring" &lt;BR /&gt;
    | head 1&lt;BR /&gt;
    | stats count&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358608#M6340</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2020-09-29T18:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Alert triggering in Splunk due to slowness</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358609#M6341</link>
      <description>&lt;P&gt;Hi @logloganathan.  It seems like maybe you need some quicker feedback.  For more direct help, please join the Splunk Slack channel via the form that is linked on the accepted answer on this page  -&lt;BR /&gt;
 &lt;A href="https://answers.splunk.com/answers/443734/is-there-a-splunk-slack-channel.html"&gt;https://answers.splunk.com/answers/443734/is-there-a-splunk-slack-channel.html&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;On Slack, you can ask your question on the &lt;CODE&gt;#n00b&lt;/CODE&gt; or &lt;CODE&gt;#general&lt;/CODE&gt; channels, and people will chime in pretty quickly to help you.  &lt;/P&gt;

&lt;P&gt;Here, you can upvote any answers that you found particularly helpful.  On the Slack channel, you can do something similar by typing &lt;CODE&gt;@somebodysname++&lt;/CODE&gt; (where &lt;CODE&gt;somebodysname&lt;/CODE&gt; is their slack handle). &lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 19:39:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-triggering-in-Splunk-due-to-slowness/m-p/358609#M6341</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-03-21T19:39:07Z</dc:date>
    </item>
  </channel>
</rss>

