Alerting

How frequently does an alert perform a query if Alert Type is set to Real-time?

splunktest_
Loves-to-Learn Lots

I have Alert Type set to Real-Time and to trigger Per-Result, but how often will it run?

What I need is on every new event to perform some calculation on the last n events, and if the calculated number meets a certain criteria, then an alert needs to be triggered. I don't have a problem writing the part of the search that does the calculation, it's setting up the alert that I am unclear on.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

if alert is a real time alert it’s running continuously and allocate whole core for it. For that reason its usually much better to run scheduled alerts every  e.g. 5-15min. Usually the frequency of alert should define based on how fast you could react and fix it. 

https://docs.splunk.com/Documentation/Splunk/8.0.5/Alert/AlertTypesOverview

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...