Alerting

How to delay the trigger alert in x minutes?

EMBautista
Engager

How can I delay the trigger of the email alert to lets say 5 minutes?

Ex.

The alert detected the response_code=500, but I would like the email alert to trigger on the 5th minute if the response_code is still the same (500). Is it possible?

Thanks!

Labels (1)
0 Karma

EMBautista
Engager

Thanks for the reply. Do you mean in the earliest and latest configuration in the time range of the alert?

 

Thanks!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Yes, use -5m@m and @m respectively to cover the previous 5 minutes

ITWhisperer
SplunkTrust
SplunkTrust

Set up the alert so that every minute it looks back 5 minutes and looks for events 5 minutes ago which are still present and only generate results when this is true.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...