Alerting

Alert not triggered

uagraw01
Motivator

In my case alert is not triggered when particular log is generated. So i checked that the person who created that alert previously has no permission for scheduler search when i verify from internal logs and beacuse of this i am not able to see any view result for job runs. So please suggest if i will create new alert by with all scheduled search permission, so it will get resolve or not ?

Means schedule search is directly proportional to alert triggered ?

 

 

Labels (1)
0 Karma
1 Solution

anilchaithu
Builder

@uagraw01 

Yes. and obviously it has to meet the alert conditions.

 

View solution in original post

0 Karma

anilchaithu
Builder

@uagraw01 

Alerts will be triggered if 

  • scheduled job runs without errors. 
  • specified alert condition met

Its always better to run the search manually to check for syntax, run time errors. and also check for alert conditions.

I am still wondering how the user without schedule_search capability was able to schedule in the first place. 

You can assign the alert to you (reassign knowledge objects) so that it runs with your capabilities.

Hope this helps.

 

0 Karma

uagraw01
Motivator

So if i have capabilities of schedule_search, then it will get resolve the issue ?

0 Karma

anilchaithu
Builder

@uagraw01 

Yes. and obviously it has to meet the alert conditions.

 

0 Karma
Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...