In my Splunk distributed environment, I have one load balancer and two search heads, and one deployment server.(No Shearch head pooling server configure).
I configured alert mail on both the search head, then I get duplicate alert mail from each search head.
Because of high availability of get alert mail I can`t enable alert mail only on one search head server, and nor I enable alert only on deployment server.
Please suggest how I get only single alerts.
Thanks in advance.
The solution is to not schedule the same alert on more than one system. The best way to do that is to add a third search head and create a search head cluster (SHC). In a SHC, alerts are automatically scheduled on an available SH so you only need to set them up once and they'll only run once.
--- If this reply helps you, an upvote would be appreciated.