Alerting

Not able to receive any alerts from SPLUNK for one particular role

Dhanush
Engager

One of the user is not able to receive any alerts if the user is trying to create an alert. However, If we create the same alert we are able to receive and marked the user as well in CC, he is able to receive the alert. As part of the trouble shooting we could see that particular role has all the capabilities to schedule a search. However, We are still encountering issue.

Need Help..If someone has inputs. That would be a great help.

 

 

@murbanek_splunk 

Labels (1)

isoutamo
SplunkTrust
SplunkTrust
When he is doing that search, he was seeing those events?
This is not a real-time alert?
r. Ismo
0 Karma

Dhanush
Engager

It's a real time alert where the query count exceeds the threshold count..The user would be receiving alerts.

As part of the troubleshooting we could receive the  exact copy of these alerts, when we create a duplicate one. However, when the user is creating he is not able to get nor us(Even if we are marked in the e-mail)

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Your user needs also [capability::schedule_rtsearch]
for do alerts based on real-time search.

Then it’s another story should he use real-time alert or scheduled alert. Personally I’m not a fan of real-time alert and until now I have succeeded to do those with normal scheduled searches.
r. Ismo

Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...