Alerting

Is it possible to schedule an alert to run every 10 Seconds?

SagarSplunk
Engager

Hi,

We have a requirement to run alert query for every 10 seconds and check for last 10 seconds data.

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The smallest interval Splunk supports is 1 minute between alert queries, unless you use real-time alerting. Most customers don't need real-time alerts. Such small intervals are usually only useful if they will be handled by some automated process. If people will be processing them then 1 minute can be too fast (5 minutes can work well).

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The smallest interval Splunk supports is 1 minute between alert queries, unless you use real-time alerting. Most customers don't need real-time alerts. Such small intervals are usually only useful if they will be handled by some automated process. If people will be processing them then 1 minute can be too fast (5 minutes can work well).

---
If this reply helps you, Karma would be appreciated.

ddrillic
Ultra Champion

An identical thought ; - ) at how to schedule an alert to run for every 10 seconds using cron?

And @SagarSplunk, please don't shoot yourself in the foot - the minimum granularity of a minute is there for a reason ...

0 Karma

SagarSplunk
Engager

But still if we want to provide is there any way using which we can achieve.

0 Karma

ddrillic
Ultra Champion

It doesn't seem so...

0 Karma

SagarSplunk
Engager

Ok..I think we have to go to Real Time alerts.

Thanks a lot for the information. 🙂

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

@sagarsplunk, if this answered your question, remember to "√Accept" the answer to award karma points 🙂 You can upvote comments too.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...