<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert Action: Max Time in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-Action-Max-Time-to-process-full-search-results/m-p/508887#M9303</link>
    <description>&lt;P&gt;Nothing happened to the alert action after I increased the maxtime.&amp;nbsp; That is why I have an open question with no accepted solution.&lt;BR /&gt;&lt;BR /&gt;I'm assuming that my initial statement about setting the maxtime wasn't clear, but I original set it in alert_actions.conf for this specific alert action.&amp;nbsp; I later changed the default.&amp;nbsp; Then in the update, I updated in savedsearches.conf since cloning it apparently copied it over to that configuration file.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2020 19:12:59 GMT</pubDate>
    <dc:creator>triest</dc:creator>
    <dc:date>2020-07-13T19:12:59Z</dc:date>
    <item>
      <title>Alert Action: Max Time to process full search results?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Action-Max-Time-to-process-full-search-results/m-p/508864#M9301</link>
      <description>&lt;P&gt;We have a search that runs that generate a large number of results; for each result we need to take an alert action (individually).&amp;nbsp; While I've increased the maxtime from the default 5min to 3h hours, looking at tracing logs from the alert action, it stops running after 5 minutes despite only having processed a fraction of the search results.&lt;/P&gt;
&lt;P&gt;For the claim its only processed a fraction of the results:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;I determined the number of search results by going to the saved search, clicking on VIew Results, and click the results set from appropriate&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;I determined the number of results processed by looking for a log message in the custom alert action that is generated at the top of the process_event function -- the Splunk add-on builder was used to build the custom alert action.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;To increase the maxtime, I initially set it just for this alert action; the search head is dedicated to running alert actions, so I then increased it globally just in case it would matter.&amp;nbsp; After both changes, I validate the setting with btool, and then restarted the Splunk instance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit: It looks like when I cloned the search so I wasn't modifying the production copy, it added more fields in the savedsearches.conf including the following setting:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;action.&amp;lt;redacted custom alert action name&amp;gt;.maxtime = 5m&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I increased that setting assuming it would be a limitation; it does not have appeared to have resolved the issue.&amp;nbsp; My current assumption is that was &lt;EM&gt;a&lt;/EM&gt; problem just not the complete problem.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 14:39:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Action-Max-Time-to-process-full-search-results/m-p/508864#M9301</guid>
      <dc:creator>triest</dc:creator>
      <dc:date>2022-08-26T14:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Action: Max Time</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Action-Max-Time-to-process-full-search-results/m-p/508882#M9302</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/221061"&gt;@triest&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What happened to the alert action run time after you increased the maxtime? Does the alert action stopped after 5 mins?&amp;nbsp;In which configuration did you update the maxtime attribute?&lt;/P&gt;&lt;P&gt;Ideally it should be in alert_actions.conf under this alert action staza.&lt;/P&gt;&lt;PRE&gt;maxtime = &amp;lt;integer&amp;gt; [m|s|h|d]&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 19:04:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Action-Max-Time-to-process-full-search-results/m-p/508882#M9302</guid>
      <dc:creator>anilchaithu</dc:creator>
      <dc:date>2020-07-13T19:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Action: Max Time</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Action-Max-Time-to-process-full-search-results/m-p/508887#M9303</link>
      <description>&lt;P&gt;Nothing happened to the alert action after I increased the maxtime.&amp;nbsp; That is why I have an open question with no accepted solution.&lt;BR /&gt;&lt;BR /&gt;I'm assuming that my initial statement about setting the maxtime wasn't clear, but I original set it in alert_actions.conf for this specific alert action.&amp;nbsp; I later changed the default.&amp;nbsp; Then in the update, I updated in savedsearches.conf since cloning it apparently copied it over to that configuration file.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 19:12:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Action-Max-Time-to-process-full-search-results/m-p/508887#M9303</guid>
      <dc:creator>triest</dc:creator>
      <dc:date>2020-07-13T19:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Action: Max Time</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Action-Max-Time-to-process-full-search-results/m-p/610960#M14191</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/221061"&gt;@triest&lt;/a&gt;&amp;nbsp; : Is your issue is resolved. I also have same issue. If it is fixed, please share the steps.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 14:09:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Action-Max-Time-to-process-full-search-results/m-p/610960#M14191</guid>
      <dc:creator>ddvali</dc:creator>
      <dc:date>2022-08-26T14:09:18Z</dc:date>
    </item>
  </channel>
</rss>

