Alerting

Crazy alert

christinmb
Path Finder

Hello, I'm monitoring my PercentFreeSpace in some of my servers so I configurated an alert when the PercentFreeSpace<15 with Time range of 15m and running every minute the search, the problem comes when I want to verify the alert results: I GET 0 EVENTS MATCHING MY SEARCH!

Any idea why this is happening?
Thanks in advanced

0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

That could just mean that you don't have any servers with PercentFreeSpace less than 15%. We would expect no results to show up in that case. Why don't you try it as a search and adjust the number and see if indeed the alert should be bringing back something. If you edit your original question with the search, that would help as well.

View solution in original post

0 Karma

sdaniels
Splunk Employee
Splunk Employee

That could just mean that you don't have any servers with PercentFreeSpace less than 15%. We would expect no results to show up in that case. Why don't you try it as a search and adjust the number and see if indeed the alert should be bringing back something. If you edit your original question with the search, that would help as well.

0 Karma

sdaniels
Splunk Employee
Splunk Employee

I think it might be sending you the results 'always' even though it's not a match, and essentially alerting every time that search runs.

0 Karma

christinmb
Path Finder

Ok, i'll try that, but why do i get an alert if the condition doesnt meets?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Try changing the alert condition from 'always' to 'if number of events' greater than 0.

0 Karma

christinmb
Path Finder
0 Karma

sdaniels
Splunk Employee
Splunk Employee

You didn't say in your question that you were getting the alerts so didn't realize that. Can you post the search details.

0 Karma

christinmb
Path Finder

But why am I getting tons of alerts if the results doesnt match?

0 Karma

emiller42
Motivator

Can you provide sample events and the actual search you're running?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...