Alerting

Alert configuration: How do we see the Alert type for “Real-time” instead of a scheduled option only?

strawberry28
Explorer

We want the alert type to be in real-time and send an alert only if the search query met the condition not to run every minute even though it does not have any result (to avoid spam alerts). How do we see the Alert type for “Real-time” ? instead of a scheduled option only. Because on our end there where no options like that it is automatically tag as "scheduled" on the alert type.

Labels (3)
Tags (2)
0 Karma

somesoni2
Revered Legend

The real-time search run more frequent than scheduled search. The real-time search (and report/alerts) will run continuously, blocking a CPU core and server resources, and alerting whenever the alert conditions are met. Whereas the scheduled searches, even the ones which are schedule to run every minute, run per schedule and wait till next schedules. 

It all depends upon the response time for you alerts (how soon you want to get notified when the alert conditions happens). If you want your alert to notify you almost immediately, choose real-time alerting (https://docs.splunk.com/Documentation/Splunk/8.2.6/Search/Aboutrealtimesearches), assuming you know the performance drawback of real-time searches and accept it. If you're ok to wait 1 minute (or 5 minute) before you know about the issue, choose the scheduled time as it'll be less noisy.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...