<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371212#M6566</link>
    <description>&lt;P&gt;Okay, then this seems to be a different issue. I was just guessing as I saw a few issues regarding realtime search with 7.1 recently. &lt;/P&gt;</description>
    <pubDate>Tue, 01 May 2018 10:30:55 GMT</pubDate>
    <dc:creator>xpac</dc:creator>
    <dc:date>2018-05-01T10:30:55Z</dc:date>
    <item>
      <title>Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371207#M6561</link>
      <description>&lt;P&gt;I have been using Splunk Enterprise 7.0.3 to do real-time search alert trigger without any issues previously. Recently, I attempt to upgrade Splunk Enterprise to 7.1.0 and found some weird problem with the alert trigger.&lt;/P&gt;

&lt;P&gt;This is the setup I have:&lt;BR /&gt;
1. Using amqp-ta plugin to consume messages from RabbitMQ into IndexA.&lt;BR /&gt;
2. An alert trigger running on All Time (real-time) search on IndexA to find newly indexed events.&lt;BR /&gt;
3. The alert is trigger per result.&lt;BR /&gt;
4. Each alert has 2 actions: Custom Action to write a result to another RabbitMQ Exchange and also log the event to another index.&lt;/P&gt;

&lt;P&gt;Problem:&lt;BR /&gt;
Whenever a new event is being added to IndexA, it will trigger repeatedly trigger the alert action. All the alert action search result is showing the same event that was added. This trigger will continue infinitely until I disable the Alert.&lt;/P&gt;

&lt;P&gt;I'm not sure if there are any changes to the architecture of Real-time search alert trigger from 7.0.3 to 7.1.0. Any help would be greatly appreciated! &lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 10:07:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371207#M6561</guid>
      <dc:creator>pweijian</dc:creator>
      <dc:date>2018-04-30T10:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371208#M6562</link>
      <description>&lt;P&gt;I've no ready solution, but did you try changing it to scheduled (every minute) search and see if it still happens? &lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 12:24:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371208#M6562</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-04-30T12:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371209#M6563</link>
      <description>&lt;P&gt;Are you, by any chance, running on the free license? There is a known bug with realtime and the free license on 7.1.0.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 22:37:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371209#M6563</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-04-30T22:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371210#M6564</link>
      <description>&lt;P&gt;Hi xpac, thanks for your suggestion. I did tried that and scheduled search is working fine. But my use-case would need to real-time search as I need alerts to be send out immediately when an event is detected.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 03:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371210#M6564</guid>
      <dc:creator>pweijian</dc:creator>
      <dc:date>2018-05-01T03:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371211#M6565</link>
      <description>&lt;P&gt;I have tried on both free license and paid license both are having the same problem.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 03:27:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371211#M6565</guid>
      <dc:creator>pweijian</dc:creator>
      <dc:date>2018-05-01T03:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371212#M6566</link>
      <description>&lt;P&gt;Okay, then this seems to be a different issue. I was just guessing as I saw a few issues regarding realtime search with 7.1 recently. &lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 10:30:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371212#M6566</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-01T10:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371213#M6567</link>
      <description>&lt;P&gt;You said that your alert is set at All Time. So, &lt;BR /&gt;
1. isn't this the reason that your search is meeting the criteria for the same event every time and hence you are seeing it repeatedly ?&lt;BR /&gt;
2. Could you add another action on your alert - "Add in Triggered Alerts". And then after your alert triggers, use the dispatched search from "Activity - &amp;gt; Triggered Alerts" from the navigation bar and analyse a few of the results that your alert is generating.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 11:06:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371213#M6567</guid>
      <dc:creator>amitm05</dc:creator>
      <dc:date>2018-05-01T11:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371214#M6568</link>
      <description>&lt;P&gt;are you saying that you used all-time realtime in 7.0.3 and didn’t recieve repeat alerts?&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 11:41:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371214#M6568</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2018-05-01T11:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371215#M6569</link>
      <description>&lt;P&gt;yup, all works fine in 7.0.3.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 14:41:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371215#M6569</guid>
      <dc:creator>pweijian</dc:creator>
      <dc:date>2018-05-01T14:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371216#M6570</link>
      <description>&lt;P&gt;Hi amitm05,&lt;/P&gt;

&lt;P&gt;From my understanding, All Time (real-time) search alert only searches new events coming into the indexer. Once the event is indexed, it should not show up in the search result of the all time real-time search query. This is working well in previous version of Splunk before I tried the new release of Splunk Version 7.1.0.&lt;/P&gt;

&lt;P&gt;I have tried to remove all my alert action and just adding the "Add in Triggered Alerts" action. Once an event trigger the alert, I keep receive constant stream of triggered alerts result under the triggered alert page. Each triggered result is showing the same set of results.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 14:47:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371216#M6570</guid>
      <dc:creator>pweijian</dc:creator>
      <dc:date>2018-05-01T14:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371217#M6571</link>
      <description>&lt;P&gt;k please open a support case and provide the saved search configs. I have asked our search teams to take a look and advise. &lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 16:05:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371217#M6571</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2018-05-01T16:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371218#M6572</link>
      <description>&lt;P&gt;The default backfill for real time searches is set to true. You might want to check that in your limits.conf and set it to false. You will find this setting in "realtime" stanza. Something like:&lt;/P&gt;

&lt;P&gt;[realtime]&lt;/P&gt;

&lt;P&gt;default_backfill = &lt;BR /&gt;
* Specifies if windowed real-time searches should backfill events&lt;BR /&gt;
* Defaults to true&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 19:35:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371218#M6572</guid>
      <dc:creator>amitm05</dc:creator>
      <dc:date>2018-05-01T19:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371219#M6573</link>
      <description>&lt;P&gt;Hi mmodestino, thank you. I have filed a support case and will be meeting up with Splunk support team on WebEx for live troubleshooting.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 10:09:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371219#M6573</guid>
      <dc:creator>pweijian</dc:creator>
      <dc:date>2018-05-02T10:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371220#M6574</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I'm also having this issue since upgrading from 7.0.3 to 7.1.0 (enterprise version) yesterday.&lt;/P&gt;

&lt;P&gt;I have multiple alerts set up as "All time (real-time)", and on previous versions of Splunk I would receive one email when the alert triggered.&lt;/P&gt;

&lt;P&gt;Now I receive a constant stream of the same email until I disable the alert in Splunk.&lt;/P&gt;

&lt;P&gt;I tried setting default_backfull to false in my limits.conf as described above, but it hasn't helped unfortunately.&lt;/P&gt;

&lt;P&gt;I'm still investigating, so I'll drop any other details I find in here...&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 18:01:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371220#M6574</guid>
      <dc:creator>agamemnon23</dc:creator>
      <dc:date>2018-05-02T18:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371221#M6575</link>
      <description>&lt;P&gt;Hi agamemnon23, I have met up with Splunk support team in live troubleshooting session and the conclusion is that the complex search query is causing the issue we are facing. And this is only happening on Splunk 7.1.0.&lt;/P&gt;

&lt;P&gt;To illustrate more...for search query,  (index="test_index"), this will only trigger one alert per result. But for search query, (index="test_index" | table _raw), the repeating alert trigger problem will reappear.&lt;/P&gt;

&lt;P&gt;I will keep you posted if I got further updates from Splunk regarding this issue.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371221#M6575</guid>
      <dc:creator>pweijian</dc:creator>
      <dc:date>2020-09-29T19:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371222#M6576</link>
      <description>&lt;P&gt;Hi pweijian, thanks for posting this update - I really appreciate it!&lt;/P&gt;

&lt;P&gt;I have just tried a similar search to the one you suggested, and I am getting the same results as you:&lt;/P&gt;

&lt;P&gt;source="/path/to/my/syslog/files/*"&lt;BR /&gt;
sourcetype="syslog"&lt;BR /&gt;
| search "my_search_string"&lt;/P&gt;

&lt;P&gt;This sends one alert ^^^&lt;/P&gt;

&lt;P&gt;source="/path/to/my/syslog/files/*"&lt;BR /&gt;
sourcetype="syslog"&lt;BR /&gt;
| search "my_search_string"&lt;BR /&gt;
| table my_field1, my_field2, my_field3&lt;/P&gt;

&lt;P&gt;This sends multiple continuous alerts ^^^&lt;/P&gt;

&lt;P&gt;My searches really are not that complex, so I am surprised at the difference.&lt;BR /&gt;
I will also raise a support ticket with Splunk.&lt;/P&gt;

&lt;P&gt;Thanks again, and likewise - I will let you know if I find out anything more.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371222#M6576</guid>
      <dc:creator>agamemnon23</dc:creator>
      <dc:date>2020-09-29T19:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371223#M6577</link>
      <description>&lt;P&gt;This issue i faced it for  our customer, but once i restarted all the services and now its working fine. &lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 12:59:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371223#M6577</guid>
      <dc:creator>jitumanidas</dc:creator>
      <dc:date>2018-05-03T12:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371224#M6578</link>
      <description>&lt;P&gt;Hi agamemnon23, I have some updates from Splunk support. He is suspecting that this is a potential bug and he has filed an internal ticket for Splunk engineering team to look into this issue. Will keep you posted if there is more update from them.&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 01:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371224#M6578</guid>
      <dc:creator>pweijian</dc:creator>
      <dc:date>2018-05-08T01:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371225#M6579</link>
      <description>&lt;P&gt;Thanks for the update peijian!&lt;/P&gt;

&lt;P&gt;We are still experiencing the issue, but we've reconfigured most of our alerts to use simpler queries in the meantime.  I haven't raised a support ticket as yet unfortunately due to other work.&lt;/P&gt;

&lt;P&gt;I'll keep you posted when I do/when I find out any more.&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 16:21:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371225#M6579</guid>
      <dc:creator>agamemnon23</dc:creator>
      <dc:date>2018-05-10T16:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there an All Time (real-time) Alert Trigger in Splunk Enterprise 7.1.0?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371226#M6580</link>
      <description>&lt;P&gt;Hi agamemnon23, Splunk support has confirmed this issue as a bug and have added this issues into the known issue for Version 7.1.0. There is no workaround for this issue in Version 7.1.0. and they will fix this problem in Release 7.1.2. You can refer to bug number SPL-154136 in &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.0/ReleaseNotes/KnownIssues"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.0/ReleaseNotes/KnownIssues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 08:24:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-is-there-an-All-Time-real-time-Alert-Trigger-in-Splunk/m-p/371226#M6580</guid>
      <dc:creator>pweijian</dc:creator>
      <dc:date>2018-05-24T08:24:54Z</dc:date>
    </item>
  </channel>
</rss>

