<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert Triggering only once even if set to 'Per Result' in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401374#M7080</link>
    <description>&lt;P&gt;I downvoted this post because not pertinent: if you have a scheduled alert it should fire more actions according to the number or results.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jul 2019 09:19:09 GMT</pubDate>
    <dc:creator>marcoscala</dc:creator>
    <dc:date>2019-07-23T09:19:09Z</dc:date>
    <item>
      <title>Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401365#M7071</link>
      <description>&lt;P&gt;I have created a scheduled alert that looks for results over a time period and if there are events, it has to send an email for every result. This email alert creates a ticket in our ticketing portal. &lt;BR /&gt;
Incase if there are 10 results in that time period, Splunk should send 10 emails. But instead Splunk triggers only once and send all the results in one single email. This is weird and I am trying to find solution to it.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Below is my Alert Configuration:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Alert Type: Scheduled Run on Cron Schedule
Time Range: last 15 minutes.
Cron Expression: 0,15,30,45 * * * *
Trigger alert when: Number of results &amp;gt; 0
Trigger: For each Result
Throttle: Unchecked.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When the alert triggers, it generates only one alert with the first result and does not trigger anything for the rest. I want to know what I am missing. I see there are 10 results but only one alert.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 09:01:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401365#M7071</guid>
      <dc:creator>ashutoshab</dc:creator>
      <dc:date>2019-04-08T09:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401366#M7072</link>
      <description>&lt;P&gt;Hey @ashutoshab , &lt;/P&gt;

&lt;P&gt;which Splunk version are you using?&lt;BR /&gt;
Also can you post the specific stanza from the savedsearches.conf&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 10:51:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401366#M7072</guid>
      <dc:creator>horsefez</dc:creator>
      <dc:date>2019-04-08T10:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401367#M7073</link>
      <description>&lt;P&gt;I am using Splunk Enterprise 7.2.4&lt;/P&gt;

&lt;P&gt;Below is my Stanza&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[STANZA NAME]
action.email = 1
action.email.include.results_link = 0
action.email.include.view_link = 0
action.email.mailserver = localhost
action.email.message.alert = {"RANDOM TEXT
}}
action.email.priority = 1
action.email.subject = &amp;lt;RANDOM TEXT&amp;gt;
action.email.to = RANDOM EMAIL ADDRESS
alert.digest_mode = 0
alert.expires = 1h
alert.severity = 4
alert.suppress = 0
alert.track = 1
counttype = number of events
cron_schedule = 0,15,30,45 * * * *
description = RANDOM DESCRIPTION
dispatch.earliest_time = -15m
dispatch.latest_time = now
display.events.type = raw
display.general.type = statistics
display.page.search.mode = verbose
display.page.search.tab = statistics
enableSched = 1
quantity = 0
relation = greater than
request.ui_dispatch_app = search
request.ui_dispatch_view = search
search = &amp;lt;SEARCH STRING&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 08 Apr 2019 12:13:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401367#M7073</guid>
      <dc:creator>ashutoshab</dc:creator>
      <dc:date>2019-04-08T12:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401368#M7074</link>
      <description>&lt;P&gt;Waiting for an answer. I feel this might be a bug.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 22:40:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401368#M7074</guid>
      <dc:creator>ashutoshab</dc:creator>
      <dc:date>2019-05-02T22:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401369#M7075</link>
      <description>&lt;P&gt;what is your search looks like?&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 16:46:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401369#M7075</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-05-03T16:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401370#M7076</link>
      <description>&lt;P&gt;Hey @ashutoshab,&lt;/P&gt;

&lt;P&gt;Here you are creating schedule alert with time range 15 min so alert is getting run every 15 min. If you want your alerts should run and send email on every event so you should create real time alerts. Real - time alerts will be useful to monitor events or event patterns as they happen.&lt;/P&gt;

&lt;P&gt;You can use this splunk documentation as reference to create real-time alerts.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Alert/DefineRealTimeAlerts"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Alert/DefineRealTimeAlerts&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 06:13:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401370#M7076</guid>
      <dc:creator>anil15694</dc:creator>
      <dc:date>2019-05-17T06:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401371#M7077</link>
      <description>&lt;P&gt;Yes, I know that, but for similar scheduled search, for some other query, I receive alert for every event. I mean, it has a different query but similar schedule of 15 mins. If there are 10 events, I receive 10 emails.&lt;/P&gt;

&lt;P&gt;Here, it send only 1 email for everything.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 12:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401371#M7077</guid>
      <dc:creator>ashutoshab</dc:creator>
      <dc:date>2019-05-20T12:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401372#M7078</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;index=&amp;lt;someIndexName&amp;gt; sourcetype="&amp;lt;someSourceType&amp;gt;" &amp;lt;SomeField&amp;gt;=* | table eventType, sender, headerFrom, recipient{}, toAddresses{}, subject, imposterScore, GUID, messageTime, phishScore, spamScore, quarantineFolder, senderIP, messageID, threatsInfoMap{}.classification, threatsInfoMap{}.threatUrl, threatsInfoMap{}.threatID, threatsInfoMap{}.campaignID, threatsInfoMap{}.threat, threatsInfoMap{}.threatStatus, threatsInfoMap{}.threatTime, threatsInfoMap{}.threatType
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 20 May 2019 13:01:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401372#M7078</guid>
      <dc:creator>ashutoshab</dc:creator>
      <dc:date>2019-05-20T13:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401373#M7079</link>
      <description>&lt;P&gt;I downvoted this post because not pertinent: if you have a scheduled alert it should fire more actions according to the number or results.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 09:19:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401373#M7079</guid>
      <dc:creator>marcoscala</dc:creator>
      <dc:date>2019-07-23T09:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401374#M7080</link>
      <description>&lt;P&gt;I downvoted this post because not pertinent: if you have a scheduled alert it should fire more actions according to the number or results.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 09:19:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401374#M7080</guid>
      <dc:creator>marcoscala</dc:creator>
      <dc:date>2019-07-23T09:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401375#M7081</link>
      <description>&lt;P&gt;Hi @ashutoshab,&lt;/P&gt;

&lt;P&gt;Is it possible to make your query generic and share ?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 12:47:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401375#M7081</guid>
      <dc:creator>snigdhasaxena</dc:creator>
      <dc:date>2019-07-23T12:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Triggering only once even if set to 'Per Result'</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401376#M7082</link>
      <description>&lt;P&gt;@ashutoshab ,seems like your throttle alert is on , which will accumulate all the events every 15mins and react at once.&lt;BR /&gt;
You can try scheduling the alert in real time with throttle disabled.&lt;/P&gt;

&lt;P&gt;Else you can try something like below&lt;/P&gt;

&lt;P&gt;The other way round can be to add a counter or a variable condition in your alert query like below.&lt;BR /&gt;
example : | stats phone by state " into the search and create a custom alert trigger such as " eval count = if(search state =received,1,0) |search  count =1 (in your case to trigger every event)".&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 12:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Triggering-only-once-even-if-set-to-Per-Result/m-p/401376#M7082</guid>
      <dc:creator>Sujithkumarkb</dc:creator>
      <dc:date>2019-07-23T12:59:57Z</dc:date>
    </item>
  </channel>
</rss>

