Alerting

Basic alert not triggering

ofirbs
New Member

Hi,

I have 2 Splunk servers with the same alert on both of them.
One is triggering the alert and the other one is not.

Even by configuring the most basic alert search :

|noop|stats count|eval count = count + 1

which returns 1 line with count 1

  • "Add to triggered alerts" is configured
  • alert is running every minute with cron.
  • number of results is greater than 0

One of them triggers and the other won't even though they are the same, so I think that there is something else outside the alert configuration.

What can I verify?

Thanks.

0 Karma

woodcock
Esteemed Legend

In later versions of Splunk (not sure when it changed), you have to use the Add Actions button and select the Add to Triggered Alerts alert action. Perhaps one of your Search Heads is an older version of Splunk or perhaps it is configured in such a way that this action is always auto-added. In any case, you should be able to manually add this to the ones that don't have it.

0 Karma

Richfez
SplunkTrust
SplunkTrust

By the alert not trigger, what exactly do you mean? If you look at jobs, does it show up there? Or just that, say, it won't send you an email? Because for the latter I'd check for differences in email setup between the two, AND check that whatever you are relaying through has allowed both servers to do this.

0 Karma

ofirbs
New Member

I mean that I don't see it in Activity -> Triggered Alerts, and neither in the bottom of the page of the alert where it says "There are no fired events for this alert."

The other alert does appear on both the places though on the second Splunk.

0 Karma

burwell
SplunkTrust
SplunkTrust

How about in the job history?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...