Alerting

In a search head cluster, is it expected behavior for only the captain to have all the alerts, not the other cluster members?

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I'm passing from a single Search Head (with four Indexers) to a Search Head Cluster.
I have three Search Heads: one that is working alone, and the other two are configured as a SH cluster.
I enabled alerts both in the standalone SH and in the clustered ones.
I checked if the standalone SH has the same triggered alerts of the other two SHs, and this is correct.
The strange thing I found is that in the clustered SHs, one (the Captain) has all the alerts and the other none!

Can someone help me to understand if this is expected behavior or not, before putting this cluster in production (inserting in it also the stand alone SH)?
I already saw documentation and answers, but from your experience, anyone found a behavior like this?

Thank you.
Bye.
Giuseppe

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Probably the problem was that a Search Head Cluster must have at least three nodes.
Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Probably the problem was that a Search Head Cluster must have at least three nodes.
Bye.
Giuseppe

Masa
Splunk Employee
Splunk Employee

Nope I haven't seen such behavior.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...