How frequently does an alert perform a query if Alert Type is set to Real-time?

Loves-to-Learn Lots

I have Alert Type set to Real-Time and to trigger Per-Result, but how often will it run?

What I need is on every new event to perform some calculation on the last n events, and if the calculated number meets a certain criteria, then an alert needs to be triggered. I don't have a problem writing the part of the search that does the calculation, it's setting up the alert that I am unclear on.

Labels (1)
0 Karma



if alert is a real time alert it’s running continuously and allocate whole core for it. For that reason its usually much better to run scheduled alerts every  e.g. 5-15min. Usually the frequency of alert should define based on how fast you could react and fix it.

r. Ismo

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!