Alerting

How to prevent duplicate alerts with multiple search heads

arun_kant_sharm
Path Finder

Hi Experts,

In my Splunk distributed environment, I have one load balancer and two search heads, and one deployment server.(No Shearch head pooling server configure).
I configured alert mail on both the search head, then I get duplicate alert mail from each search head.
Because of high availability of get alert mail I can`t enable alert mail only on one search head server, and nor I enable alert only on deployment server.
Please suggest how I get only single alerts.
Thanks in advance.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The solution is to not schedule the same alert on more than one system. The best way to do that is to add a third search head and create a search head cluster (SHC). In a SHC, alerts are automatically scheduled on an available SH so you only need to set them up once and they'll only run once.

---
If this reply helps you, an upvote would be appreciated.

richgalloway
SplunkTrust
SplunkTrust

I removed the search-head-clustering tag because this obviously is not a SHC situation.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.