Alerting
Highlighted

How frequently does an alert perform a query if Alert Type is set to Real-time?

Loves-to-Learn

I have Alert Type set to Real-Time and to trigger Per-Result, but how often will it run?

What I need is on every new event to perform some calculation on the last n events, and if the calculated number meets a certain criteria, then an alert needs to be triggered. I don't have a problem writing the part of the search that does the calculation, it's setting up the alert that I am unclear on.

Labels (1)
0 Karma
Highlighted

Re: How frequently does an alert perform a query if Alert Type is set to Real-time?

Motivator

Hi

if alert is a real time alert it’s running continuously and allocate whole core for it. For that reason its usually much better to run scheduled alerts every  e.g. 5-15min. Usually the frequency of alert should define based on how fast you could react and fix it. 

https://docs.splunk.com/Documentation/Splunk/8.0.5/Alert/AlertTypesOverview

r. Ismo

0 Karma