Alerting

Alerts not triggering, but the same search has results

bazcurtis178
Explorer

Hi,

I have 6 Alerts that run on a schedule. Only one of them is working. If I run the search results come back that match. Why would they not be triggering?

 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @bazcurtis178,

did you tested the searches without results in the same time period or after when you checked it?

Please try to run it in the same time period of the schedules alert.

Ciao.

Giuseppe

bazcurtis178
Explorer

I think I have cracked it. I think the data coming into index could come in and miss the alert. I have now tweaked the alerts to be cron jobs and I am collecting the data a little more quickly, 15 minutes instead of 20. Thanks for the help.

0 Karma

bazcurtis178
Explorer

I have been checking them minutes after they should trigger. If they should trigger at 20 minutes past the hour I was checking at 25 minutes past.

I have changed them to cron jobs now rather than the GUI x past the hour option. One has already triggered.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...