Alerting

How frequently does an alert perform a query if Alert Type is set to Real-time?

splunktest_
Loves-to-Learn Lots

I have Alert Type set to Real-Time and to trigger Per-Result, but how often will it run?

What I need is on every new event to perform some calculation on the last n events, and if the calculated number meets a certain criteria, then an alert needs to be triggered. I don't have a problem writing the part of the search that does the calculation, it's setting up the alert that I am unclear on.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

if alert is a real time alert it’s running continuously and allocate whole core for it. For that reason its usually much better to run scheduled alerts every  e.g. 5-15min. Usually the frequency of alert should define based on how fast you could react and fix it. 

https://docs.splunk.com/Documentation/Splunk/8.0.5/Alert/AlertTypesOverview

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...