<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk sending invalid Email Alerts in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-sending-invalid-Email-Alerts/m-p/457752#M129272</link>
    <description>&lt;P&gt;You may be getting events arriving later into the instance, what could explain the variation in numbers you;re seeing&lt;/P&gt;

&lt;P&gt;Check the _indextime field in those events to verify that&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2019 07:46:27 GMT</pubDate>
    <dc:creator>tiagofbmm</dc:creator>
    <dc:date>2019-07-09T07:46:27Z</dc:date>
    <item>
      <title>Splunk sending invalid Email Alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-sending-invalid-Email-Alerts/m-p/457751#M129271</link>
      <description>&lt;P&gt;I am running a query to alert me if the sum of a particular property  &amp;lt; 400000. I get alert most times saying the count &amp;lt; 400000.  I go and run the query manually for that specific time describred in alert email.. I see that the count is well over 400000. What am I missing here?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=app host="aws-service-ip*" sourcetype="aws-fht-service-transactions" SVCPushCounter earliest="08/07/2019:19:00:00" latest="08/07/2019:19:30:00"| stats sum(SVCPushCounter) as totalBySvc by Partner| where  (Partner=CVS AND totalBySvc&amp;lt;4000000) )
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 08 Jul 2019 19:54:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-sending-invalid-Email-Alerts/m-p/457751#M129271</guid>
      <dc:creator>rmuraly</dc:creator>
      <dc:date>2019-07-08T19:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sending invalid Email Alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-sending-invalid-Email-Alerts/m-p/457752#M129272</link>
      <description>&lt;P&gt;You may be getting events arriving later into the instance, what could explain the variation in numbers you;re seeing&lt;/P&gt;

&lt;P&gt;Check the _indextime field in those events to verify that&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 07:46:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-sending-invalid-Email-Alerts/m-p/457752#M129272</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2019-07-09T07:46:27Z</dc:date>
    </item>
  </channel>
</rss>

