Alerting

My alert in SPLUNK is not triggering

SPLAUR
Engager

Dear Splunk community,

I have a search in Splunk that generates results:

index="myindex" message_id="AU2" | stats count by src | search count > 2

It basically searches the index for events of type "AU2" and shows an alert when they are greater than 2.

SPLAUR_0-1741716761825.png


I have created several alerts with different modes:
Real-time Mode

SPLAUR_1-1741716795935.png

 

Scheduled Mode

SPLAUR_2-1741716804090.png

 

When I run:

index=_internal sourcetype=scheduler savedsearch_name="PRUEBA Scheduled"

It shows the following:

SPLAUR_3-1741716816307.png

 

Could you tell me what I might be doing wrong or what I might be missing?

Regards.

 

Labels (4)
0 Karma
1 Solution

SPLAUR
Engager

Hi @livehybrid

First of all, thank you for your quick response.

It is greatly appreciated.

In the end, it was a much simpler mistake; I forgot to include the port in the SMTP FQDN since it is under SSL.

Regards

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Regard the second alert - I think that looks like it should fire, although there is no supression enabled and the crontab is set to run every minute - so you might find you get a lot of alerts! 

Its worth checking in the _audit index to see if the search is executing successfully and if it alerts. Also, have you checked your Spam folder incase the emails have ended up there? Have you previously been able to send an email from Splunk and received it in your inbox?

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

livehybrid
SplunkTrust
SplunkTrust

Hi @SPLAUR 

it’s generally not advised to use real time searching. Scheduled is much better on your system!

Also, you have the value of “1” in the supress fields box on the first alert but this should probably be “src”

 

SPLAUR
Engager

Hi @livehybrid

First of all, thank you for your quick response.

It is greatly appreciated.

In the end, it was a much simpler mistake; I forgot to include the port in the SMTP FQDN since it is under SSL.

Regards

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...