Alerting

Not able to receive any alerts from SPLUNK for one particular role

Dhanush
Engager

One of the user is not able to receive any alerts if the user is trying to create an alert. However, If we create the same alert we are able to receive and marked the user as well in CC, he is able to receive the alert. As part of the trouble shooting we could see that particular role has all the capabilities to schedule a search. However, We are still encountering issue.

Need Help..If someone has inputs. That would be a great help.

 

 

@murbanek_splunk 

Labels (1)

isoutamo
SplunkTrust
SplunkTrust
When he is doing that search, he was seeing those events?
This is not a real-time alert?
r. Ismo
0 Karma

Dhanush
Engager

It's a real time alert where the query count exceeds the threshold count..The user would be receiving alerts.

As part of the troubleshooting we could receive the  exact copy of these alerts, when we create a duplicate one. However, when the user is creating he is not able to get nor us(Even if we are marked in the e-mail)

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Your user needs also [capability::schedule_rtsearch]
for do alerts based on real-time search.

Then it’s another story should he use real-time alert or scheduled alert. Personally I’m not a fan of real-time alert and until now I have succeeded to do those with normal scheduled searches.
r. Ismo

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...