I have Alert Type set to Real-Time and to trigger Per-Result, but how often will it run?
What I need is on every new event to perform some calculation on the last n events, and if the calculated number meets a certain criteria, then an alert needs to be triggered. I don't have a problem writing the part of the search that does the calculation, it's setting up the alert that I am unclear on.
Hi
if alert is a real time alert it’s running continuously and allocate whole core for it. For that reason its usually much better to run scheduled alerts every e.g. 5-15min. Usually the frequency of alert should define based on how fast you could react and fix it.
https://docs.splunk.com/Documentation/Splunk/8.0.5/Alert/AlertTypesOverview
r. Ismo