<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Real time Alert in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Real-time-Alert/m-p/437917#M7637</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm trying to generate an alert if the result is greater than 2, but i don't have the field Real-Time as shown in the picture:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5369i7E6A0D0B08C5F680/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Is there any other way to generate this alert ?&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jul 2018 14:32:21 GMT</pubDate>
    <dc:creator>omarka</dc:creator>
    <dc:date>2018-07-13T14:32:21Z</dc:date>
    <item>
      <title>Real time Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Real-time-Alert/m-p/437917#M7637</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm trying to generate an alert if the result is greater than 2, but i don't have the field Real-Time as shown in the picture:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5369i7E6A0D0B08C5F680/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Is there any other way to generate this alert ?&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 14:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-time-Alert/m-p/437917#M7637</guid>
      <dc:creator>omarka</dc:creator>
      <dc:date>2018-07-13T14:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Real time Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Real-time-Alert/m-p/437918#M7638</link>
      <description>&lt;P&gt;Hi @omarka,&lt;/P&gt;

&lt;P&gt;You need &lt;CODE&gt;schedule_rtsearch&lt;/CODE&gt; permission to schedule a real time search. &lt;BR /&gt;
Real-time alerts can be costly in terms of computing resources, so consider using a scheduled alert when possible. You could use schedule search to run every 1 minute which should be enough in most of the uses &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.1/Alert/Definescheduledalerts"&gt;Define scheduled alerts&lt;/A&gt;. Also have a look at the &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.1/Alert/AlertSchedulingBestPractices"&gt;Best Practices&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 14:45:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-time-Alert/m-p/437918#M7638</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-07-13T14:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Real time Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Real-time-Alert/m-p/437919#M7639</link>
      <description>&lt;P&gt;There are very, Very, VERY good reasons that your admin has wisely taken away Real-Time, including:&lt;/P&gt;

&lt;P&gt;1: Any real-time anything locks 1 core on EVERY Indexer and Your Search-Head.  This does not scale.&lt;BR /&gt;
2: You don't need it.  If you cannot react to the alert in ~1s, a short-window regular search is just as effective.&lt;BR /&gt;
3: There is pipeline latency in getting events into Splunk and a real-time search may search for your event before it has even arrived on the indexer and make for many false-negatives.&lt;/P&gt;

&lt;P&gt;Despite what all of the marketing and training says, SPLUNK IS *&lt;STRONG&gt;&lt;EM&gt;NOT&lt;/EM&gt;&lt;/STRONG&gt;* A REAL-TIME PRODUCT!&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jul 2018 17:08:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Real-time-Alert/m-p/437919#M7639</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-15T17:08:37Z</dc:date>
    </item>
  </channel>
</rss>

