<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alert not getting triggered with cron schedule in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486736#M8616</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;I have configured an alert with &lt;CODE&gt;earliest=-24h&lt;/CODE&gt; and &lt;CODE&gt;head 3000&lt;/CODE&gt; and i can see from search there are lot of results are populating but I am no alerts are getting generated. Alert threshold is greater than 2 and results populating are 77&lt;BR /&gt;
I have integrated the alert with splunk. At first I thought it might the integration is broken but I am verifying from here &lt;CODE&gt;activity-&amp;gt;triggered alerts&lt;/CODE&gt; but i do not see anything&lt;BR /&gt;
&lt;A href="https://share.getcloudapp.com/kpuYKLmd"&gt;https://share.getcloudapp.com/kpuYKLmd&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I am not sure if this due to the cron and other settings, so here it is&lt;BR /&gt;
&lt;A href="https://share.getcloudapp.com/o0uD6gyX"&gt;https://share.getcloudapp.com/o0uD6gyX&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Mar 2020 14:03:40 GMT</pubDate>
    <dc:creator>praddasg</dc:creator>
    <dc:date>2020-03-06T14:03:40Z</dc:date>
    <item>
      <title>Alert not getting triggered with cron schedule</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486736#M8616</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;I have configured an alert with &lt;CODE&gt;earliest=-24h&lt;/CODE&gt; and &lt;CODE&gt;head 3000&lt;/CODE&gt; and i can see from search there are lot of results are populating but I am no alerts are getting generated. Alert threshold is greater than 2 and results populating are 77&lt;BR /&gt;
I have integrated the alert with splunk. At first I thought it might the integration is broken but I am verifying from here &lt;CODE&gt;activity-&amp;gt;triggered alerts&lt;/CODE&gt; but i do not see anything&lt;BR /&gt;
&lt;A href="https://share.getcloudapp.com/kpuYKLmd"&gt;https://share.getcloudapp.com/kpuYKLmd&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I am not sure if this due to the cron and other settings, so here it is&lt;BR /&gt;
&lt;A href="https://share.getcloudapp.com/o0uD6gyX"&gt;https://share.getcloudapp.com/o0uD6gyX&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 14:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486736#M8616</guid>
      <dc:creator>praddasg</dc:creator>
      <dc:date>2020-03-06T14:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Alert not getting triggered with cron schedule</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486737#M8617</link>
      <description>&lt;P&gt;although I am using &lt;CODE&gt;earliest&lt;/CODE&gt; but i still changed the &lt;CODE&gt;time range&lt;/CODE&gt; from alert configuration to 2 mins (earlier it was 12 hours) still no luck&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 15:22:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486737#M8617</guid>
      <dc:creator>praddasg</dc:creator>
      <dc:date>2020-03-06T15:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Alert not getting triggered with cron schedule</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486738#M8618</link>
      <description>&lt;P&gt;You need to add alert action &lt;STRONG&gt;"Add to Triggered Alerts"&lt;/STRONG&gt; to your alert then it'll appear in Activity-&amp;gt;Triggered Alerts with severity set in alert action.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 16:18:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486738#M8618</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-03-06T16:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Alert not getting triggered with cron schedule</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486739#M8619</link>
      <description>&lt;P&gt;What alert actions do you have tied to the alert? How sure are you that it fired but you did not notice? Have you checked the internal logs to verify if it fired? &lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 16:37:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486739#M8619</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2020-03-06T16:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Alert not getting triggered with cron schedule</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486740#M8620</link>
      <description>&lt;P&gt;It seems the splunk integration was broken because I did not include some text in the &lt;CODE&gt;message&lt;/CODE&gt; section. All sorted and thanks for your help&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 16:43:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-getting-triggered-with-cron-schedule/m-p/486740#M8620</guid>
      <dc:creator>praddasg</dc:creator>
      <dc:date>2020-03-06T16:43:20Z</dc:date>
    </item>
  </channel>
</rss>

