Alerting

Logevent alert : Why does trigger_timeHMS appears several times?

splunkreal
Motivator

Hello guys,

I use $trigger_timeHMS$ in logevent (triggering for each result) and I can see $trigger_timeHMS$ appears several times per tens results.

I use this token to save reporting date in raw data :

ex : schedule at 13:00 =

2019-03-20 13:00:32 19 events
2019-03-20 13:00:33 29 events
2019-03-20 13:00:34 29 events
2019-03-20 13:00:35 8 events

There is no duplicate result.

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...