Alerting

Logevent alert : Why does trigger_timeHMS appears several times?

splunkreal
Motivator

Hello guys,

I use $trigger_timeHMS$ in logevent (triggering for each result) and I can see $trigger_timeHMS$ appears several times per tens results.

I use this token to save reporting date in raw data :

ex : schedule at 13:00 =

2019-03-20 13:00:32 19 events
2019-03-20 13:00:33 29 events
2019-03-20 13:00:34 29 events
2019-03-20 13:00:35 8 events

There is no duplicate result.

Thanks.

* If this helps, please upvote or accept solution 🙂 *
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...