<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why alert is not triggering on exact time in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439985#M7670</link>
    <description>&lt;P&gt;nope, it'll trigger based on number of results. &lt;/P&gt;</description>
    <pubDate>Tue, 17 Jul 2018 16:40:57 GMT</pubDate>
    <dc:creator>chandana204</dc:creator>
    <dc:date>2018-07-17T16:40:57Z</dc:date>
    <item>
      <title>Why alert is not triggering on exact time</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439981#M7666</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;From the past one week I have been looking into my alert jobs. I found that alerts are triggering 4 minutes before from the actual trigger time. Because of this time change i missed lot of alerts. May I know the reason, why Splunk Enterprice is considering actual time? &lt;/P&gt;

&lt;P&gt;I am attaching screenshots for more understanding &lt;BR /&gt;
The below image shows my alert trigger tim&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5373iD67F4FE40952EB81/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;The below image shows the alert triggered time. Based on trigger condition it should get trigger today at 12:00 AM but it got triggered yesterday 11:56 PM. &lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5374iB41CA726C198A7F3/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Please explain me if anyone know the reason behind this issue.&lt;/P&gt;

&lt;P&gt;Thanks in Advance,&lt;BR /&gt;
Chandana&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 19:41:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439981#M7666</guid>
      <dc:creator>chandana204</dc:creator>
      <dc:date>2018-07-16T19:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why alert is not triggering on exact time</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439982#M7667</link>
      <description>&lt;P&gt;we need more information. &lt;BR /&gt;
whats the alert condition?&lt;BR /&gt;
how are you saving that file? &lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 20:15:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439982#M7667</guid>
      <dc:creator>CarsonZa</dc:creator>
      <dc:date>2018-07-16T20:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why alert is not triggering on exact time</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439983#M7668</link>
      <description>&lt;P&gt;it's a scheduled alert. It'll trigger every Monday at 12:00 AM. The output file save as PDF. &lt;/P&gt;

&lt;P&gt;I have been using this alert from past one and half month. It was triggering on exact time as specified trigger time. But from the last week it's getting trigger as mentioned above. &lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 20:58:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439983#M7668</guid>
      <dc:creator>chandana204</dc:creator>
      <dc:date>2018-07-16T20:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why alert is not triggering on exact time</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439984#M7669</link>
      <description>&lt;P&gt;Hi Chandana, &lt;BR /&gt;
are there any other trigger conditions mentioned?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 00:27:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439984#M7669</guid>
      <dc:creator>pruthvikrishnap</dc:creator>
      <dc:date>2018-07-17T00:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why alert is not triggering on exact time</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439985#M7670</link>
      <description>&lt;P&gt;nope, it'll trigger based on number of results. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 16:40:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439985#M7670</guid>
      <dc:creator>chandana204</dc:creator>
      <dc:date>2018-07-17T16:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why alert is not triggering on exact time</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439986#M7671</link>
      <description>&lt;P&gt;I believe you are misinterpreting that time stamp.   Just because the search was "created" shortly before the scheduled time does not mean that it ran early. &lt;/P&gt;

&lt;P&gt;If you add this code to the end of the alert, you will see the actual time range that is covered.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| append [| makeresults | addinfo
   | eval Time = strftime(_time,"%Y-%m-%d %H:%M:%S")
   | eval Info_min_time=strftime(info_min_time,"%Y-%m-%d %H:%M:%S") 
   | eval Info_max_time=strftime(info_max_time,"%Y-%m-%d %H:%M:%S") 
   | eval Info_search_time=strftime(info_search_time,"%Y-%m-%d %H:%M:%S") 
   | eval Now=strftime(now(),"%Y-%m-%d %H:%M:%S")
   | table Time Now Info_min_time Info_max_time Info_search_time
   ]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;CODE&gt;info_min_time&lt;/CODE&gt; and &lt;CODE&gt;info_max_time&lt;/CODE&gt; are the time bounds for events selected by the search.  &lt;CODE&gt;Info_search_time&lt;/CODE&gt; is the time the search was created.  Now is the time the search started.  Time is the time the &lt;CODE&gt;makeresults&lt;/CODE&gt; command generated its output event, which is roughly a second after now(). &lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;More likely, the problem is that events can take a few seconds (or more) to be indexed.  that is the reason that the normal practice is to schedule such a job to run a few minutes after the hour, rather than immediately on the hour.  &lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 19:13:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439986#M7671</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-08-09T19:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why alert is not triggering on exact time</title>
      <link>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439987#M7672</link>
      <description>&lt;P&gt;Thanks for your response. My alerts are triggering before the hour not after the hour. I'll use your query to make sure the selected time range. &lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Chandana&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 16:33:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-alert-is-not-triggering-on-exact-time/m-p/439987#M7672</guid>
      <dc:creator>chandana204</dc:creator>
      <dc:date>2018-08-14T16:33:07Z</dc:date>
    </item>
  </channel>
</rss>

