Alerting

My alert in SPLUNK is not triggering

SPLAUR
Engager

Dear Splunk community,

I have a search in Splunk that generates results:

index="myindex" message_id="AU2" | stats count by src | search count > 2

It basically searches the index for events of type "AU2" and shows an alert when they are greater than 2.

SPLAUR_0-1741716761825.png


I have created several alerts with different modes:
Real-time Mode

SPLAUR_1-1741716795935.png

 

Scheduled Mode

SPLAUR_2-1741716804090.png

 

When I run:

index=_internal sourcetype=scheduler savedsearch_name="PRUEBA Scheduled"

It shows the following:

SPLAUR_3-1741716816307.png

 

Could you tell me what I might be doing wrong or what I might be missing?

Regards.

 

Labels (4)
0 Karma
1 Solution

SPLAUR
Engager

Hi @livehybrid

First of all, thank you for your quick response.

It is greatly appreciated.

In the end, it was a much simpler mistake; I forgot to include the port in the SMTP FQDN since it is under SSL.

Regards

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Regard the second alert - I think that looks like it should fire, although there is no supression enabled and the crontab is set to run every minute - so you might find you get a lot of alerts! 

Its worth checking in the _audit index to see if the search is executing successfully and if it alerts. Also, have you checked your Spam folder incase the emails have ended up there? Have you previously been able to send an email from Splunk and received it in your inbox?

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

livehybrid
SplunkTrust
SplunkTrust

Hi @SPLAUR 

it’s generally not advised to use real time searching. Scheduled is much better on your system!

Also, you have the value of “1” in the supress fields box on the first alert but this should probably be “src”

 

SPLAUR
Engager

Hi @livehybrid

First of all, thank you for your quick response.

It is greatly appreciated.

In the end, it was a much simpler mistake; I forgot to include the port in the SMTP FQDN since it is under SSL.

Regards

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...