<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Increase max time for a script alert in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Increase-max-time-for-a-script-alert/m-p/392771#M114259</link>
    <description>&lt;P&gt;I am running a script from a alert which takes around 30 mins to complete . But instead my script is getting fired within5 mins or so and there are multiple instances of same script running. Manually the script works just fine. Is there a  way i can increase the time before my scripts get killed or restarted from Splunk. i am using V 7.1.2. PLease help&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jul 2019 05:50:34 GMT</pubDate>
    <dc:creator>Mansi24</dc:creator>
    <dc:date>2019-07-19T05:50:34Z</dc:date>
    <item>
      <title>Increase max time for a script alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Increase-max-time-for-a-script-alert/m-p/392771#M114259</link>
      <description>&lt;P&gt;I am running a script from a alert which takes around 30 mins to complete . But instead my script is getting fired within5 mins or so and there are multiple instances of same script running. Manually the script works just fine. Is there a  way i can increase the time before my scripts get killed or restarted from Splunk. i am using V 7.1.2. PLease help&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 05:50:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Increase-max-time-for-a-script-alert/m-p/392771#M114259</guid>
      <dc:creator>Mansi24</dc:creator>
      <dc:date>2019-07-19T05:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Increase max time for a script alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Increase-max-time-for-a-script-alert/m-p/392772#M114260</link>
      <description>&lt;P&gt;Hi, Plz Make it a schedule alert which runs on cron schedule and change its timing to every 30 minutes from Cron Expression. As shown in the screenshot:&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7343iABD5DC9E7B248F81/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 10:30:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Increase-max-time-for-a-script-alert/m-p/392772#M114260</guid>
      <dc:creator>jitendragupta</dc:creator>
      <dc:date>2019-07-19T10:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Increase max time for a script alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Increase-max-time-for-a-script-alert/m-p/392773#M114261</link>
      <description>&lt;P&gt;Thanks for your response , may be my question isn't clear. actually script takes 30 min to run and i have scheduled for every hour but splunk has limitation of running alert script for 5 mins. are you aware what changes i need to do in alerts_actions.conf file in that case. &lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 10:44:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Increase-max-time-for-a-script-alert/m-p/392773#M114261</guid>
      <dc:creator>Mansi24</dc:creator>
      <dc:date>2019-07-19T10:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Increase max time for a script alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Increase-max-time-for-a-script-alert/m-p/392774#M114262</link>
      <description>&lt;P&gt;To avoid this we have throttle option in Splunk. When your alert condition is fired, it will wait for that number of minutes which u have set in the throttle. And only after the throttle period, the next alert is fired. So this will avoid multiple instances of the same script.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 11:01:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Increase-max-time-for-a-script-alert/m-p/392774#M114262</guid>
      <dc:creator>jitendragupta</dc:creator>
      <dc:date>2019-07-19T11:01:20Z</dc:date>
    </item>
  </channel>
</rss>

