Alerting

If a search head goes down do alerts queue until it returns?

Munju1
Engager

We have one ES search head in a distributed environment.

1. If the search head goes down, do alerts queue up and trigger actions once Splunk is back up?

2. If yes, for what period of time are alerts retained for?

Thank you. 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If a search head goes down no Splunk work can be done so there is no queuing of searches/alerts.  Once the SH comes back up then searches will execute at their next interval.  There is no "catch-up".

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If a search head goes down no Splunk work can be done so there is no queuing of searches/alerts.  Once the SH comes back up then searches will execute at their next interval.  There is no "catch-up".

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...