Alerting

Alert set to medium severity but also creating high severity under alert list

palisetty
Communicator
2020-01-05 22:14:20 India Standard Time Splunk Web login attempts   search  Real-time   High    Per Result   View results |  Edit search | Delete
2020-01-05 22:14:20 India Standard Time login   search  Real-time   Medium  Digest   View results |  Edit search | Delete

I set alert to medium severity and I set it to Once, not per result. I made 5 login failures continuously. At first, I got medium as expected but then I got High. Why is this behavior?

Tags (1)
0 Karma

niketn
Legend

@palisetty can you share the saved search details (configuration from savedsearches.conf) or configuration screenshots from front-end? Also by any chance do you have multiple alerts configured instead of one?

Where are you seeing the above results, from Triggered Alert list or somewhere else? Please add more details for the community to assist you better.

Before posting code/configuration or screenshot on Splunk Answers please ensure you mask/anonymize any sensitive information.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...