Alerting

Don't Expire Alerts

raghul725
Explorer

Hello All,

Sorry to ask a silly question, I had a look around, but unable to find a solution.

When we set an alert in Splunk, there is an Expires Parameter.

I understand this is TTL for the Alert (Sorry if I have misunderstood it).

I don't want my Alert to Expire.
How can I achieve this please?

If there is no means to achieve this, is there a way to trigger a notification, when that alert is about to expire please?
I tried couple of options in alert setting, to see if splunk triggers a notification when an alert expires, I am afraid no notification was triggered.

For example set "Trigger Condition", "Trigger Time" and set the alert to Expire in 10 mins. The alert Expired but no notification was triggered via email.
I had a feeling it won't work, as Trigger Condition means - The condition that triggers the alert and NOT alert expiry - but just tried my luck!

Best Regards,

Labels (1)
0 Karma
1 Solution

493669
Super Champion

Hi @raghul725 ,
Expires Parameter in alert define the lifespan of triggered Alert basically how long you can access the result of triggered alert.
Even though you set the alert Expire in 0 min doesn't mean it won't get trigger at your scheduled time after 10 min . It will get triggerred .
Just the trigger alert results you can see trigger alert results till 10 min after alert gets trigger.
Hope this explains!

View solution in original post

0 Karma

493669
Super Champion

Hi @raghul725 ,
Expires Parameter in alert define the lifespan of triggered Alert basically how long you can access the result of triggered alert.
Even though you set the alert Expire in 0 min doesn't mean it won't get trigger at your scheduled time after 10 min . It will get triggerred .
Just the trigger alert results you can see trigger alert results till 10 min after alert gets trigger.
Hope this explains!

0 Karma

raghul725
Explorer

So essentially, what we are saying here is

Alert Expire field defines how long the alert will be visible, once triggered and does NOT set an expiry on the alert trigger i.e. alter trigger will be enabled until that is disabled manually.

0 Karma

raghul725
Explorer

brilliant thanks

0 Karma

493669
Super Champion

Yes you understand correctly. 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...