<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New Real Time Alerts not working in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66956#M930</link>
    <description>&lt;P&gt;Are the newly created/cloned alerts owned by a different user? If so, does that user have a valid email address set?&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jul 2013 16:36:51 GMT</pubDate>
    <dc:creator>jtrucks</dc:creator>
    <dc:date>2013-07-23T16:36:51Z</dc:date>
    <item>
      <title>New Real Time Alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66952#M926</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We have a number of real time alerts that are working fine (that are being generated by certain Active Directory events via the Universal Forwarder installed on the DC), but when I try to create any new real time alerts they do not seem to work; I am not receiving the email, and the Alert counter on the Searches and Reports page remains on 0.  When I run the search manually for the last 15 minutes, I get results that I would expect, so the search parameters seem to be ok.&lt;/P&gt;

&lt;P&gt;I even cloned a working rule, and created an event.  The original alert triggered, but the new cloned one did not &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2012 11:12:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66952#M926</guid>
      <dc:creator>yrajah</dc:creator>
      <dc:date>2012-09-21T11:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: New Real Time Alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66953#M927</link>
      <description>&lt;P&gt;Hello, Same issue here, i'm interested in the answer.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2012 14:36:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66953#M927</guid>
      <dc:creator>sd100</dc:creator>
      <dc:date>2012-10-04T14:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: New Real Time Alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66954#M928</link>
      <description>&lt;P&gt;+1 - me too. alerts were working, and then modified the search. now they're not. I even deleted the search, recreated it, and still not getting results.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2013 09:39:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66954#M928</guid>
      <dc:creator>brettcave</dc:creator>
      <dc:date>2013-05-03T09:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: New Real Time Alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66955#M929</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I still get issues with real time alerting every now and then.  The last one I had (maybe not exactly the same as this) was resolved by a restart of the splunk services.  I would be interested to know if this fixes your problem?&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2013 10:49:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66955#M929</guid>
      <dc:creator>yrajah</dc:creator>
      <dc:date>2013-05-03T10:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: New Real Time Alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66956#M930</link>
      <description>&lt;P&gt;Are the newly created/cloned alerts owned by a different user? If so, does that user have a valid email address set?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2013 16:36:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66956#M930</guid>
      <dc:creator>jtrucks</dc:creator>
      <dc:date>2013-07-23T16:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: New Real Time Alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66957#M931</link>
      <description>&lt;P&gt;nope, owned by my user. i have a valid email address. the alerts started working after a splunk server restart.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2013 16:41:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66957#M931</guid>
      <dc:creator>brettcave</dc:creator>
      <dc:date>2013-07-23T16:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: New Real Time Alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66958#M932</link>
      <description>&lt;P&gt;You should post an answer that a reboot fixed it and then accept the answer. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2013 16:51:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66958#M932</guid>
      <dc:creator>jtrucks</dc:creator>
      <dc:date>2013-07-23T16:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: New Real Time Alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66959#M933</link>
      <description>&lt;P&gt;I did have further problems with this, and I now believe I found the cause.&lt;/P&gt;

&lt;P&gt;In my case I think it was simply because I had too many real time searches running, and was hitting my my limit.  I believe that you can change the limit in limits.conf as long as your hardware is up to the job.  I just cleaned up some stuff, and changed some real time searches/alerts to a daily report and have not had any issues since.  &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Limitsconf"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Limitsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.1/Search/Realtimeperformanceandlimitations"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.1/Search/Realtimeperformanceandlimitations&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2013 09:17:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66959#M933</guid>
      <dc:creator>yrajah</dc:creator>
      <dc:date>2013-07-24T09:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: New Real Time Alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66960#M934</link>
      <description>&lt;P&gt;Hey dudes.&lt;BR /&gt;
I am fighting the same problems, but I do have some clues. Mine I beleive are related to LDAP so I don't know your environment but configured to LDAP can be and issue.&lt;BR /&gt;
My real time alerts changed everytime I changed added more complex strings to LDAP.&lt;/P&gt;

&lt;P&gt;I have other ideas about working around this but it takes time.&lt;/P&gt;

&lt;P&gt;jim &lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 23:09:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66960#M934</guid>
      <dc:creator>jkeellogic</dc:creator>
      <dc:date>2016-01-23T23:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: New Real Time Alerts not working</title>
      <link>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66961#M935</link>
      <description>&lt;P&gt;Thanks for pointing that out, idk if i ever thoght about limits here.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 16:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/New-Real-Time-Alerts-not-working/m-p/66961#M935</guid>
      <dc:creator>salem34</dc:creator>
      <dc:date>2017-02-09T16:51:25Z</dc:date>
    </item>
  </channel>
</rss>

