Alerting

Does saved triggered alerts results utilized user disk usage quota until alert expiry?

eranga
Engager

I have alerts configured expires after 100days and scheduled to execute search query every 10mins. I can see alert search job is available under "| rest /services/search/jobs" and utilizing disk usage.

I could not find anything about this in the logs. Could someone help me to understand relationship between disk quota utilization vs triggered alert retention period?   

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Please understand that alerts *never* expire.  They will continue to run until you disable or delete them.

What *does* expire are the alert *results*.  That is the data found by the query that ran to trigger (or not) the alert.  That data is kept in the search head and is subject to disk space limits based on the role of the user running the alert.  Without such limits, the SH risks running out of space to use to store more search results.

IMO, there's very little need to preserve alert results beyond the standard 2p.  Perhaps 24 or 72 hours, but not 100 days.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Please understand that alerts *never* expire.  They will continue to run until you disable or delete them.

What *does* expire are the alert *results*.  That is the data found by the query that ran to trigger (or not) the alert.  That data is kept in the search head and is subject to disk space limits based on the role of the user running the alert.  Without such limits, the SH risks running out of space to use to store more search results.

IMO, there's very little need to preserve alert results beyond the standard 2p.  Perhaps 24 or 72 hours, but not 100 days.

---
If this reply helps you, Karma would be appreciated.

eranga
Engager

Thank you for the clarification @richgalloway 

 

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...