Alerting

Real time alerts are not triggering even though results are present in search result.

saibal6
Path Finder

I have tested with my real-time alert mail notification with few results. It is working properly and always gave me the exact and proper result what I wanted.

But we I set all my 52 real-time mail alerts notification with the same settings what I have previously tested, after that day I didn't get any mail notification for any alerts but the real time errors are present in search result, it's showing me in Splunk whenever I run the search result but it didn't inform me by mail alerts.

My real time mail alert configuration :
Enabled : Yes. Disable
App : search
Permissions : Private. Owned by admin. Edit
Alert Type : Real-time. Edit
Trigger Condition :
Trigger alert when : Number of Results is > 0 in 6 hours. Edit
Trigger : Once
Throttle : Checked
Suppress triggering for : 24 Hours.

Can anyone help me on this matter? Please let me know if you need more information on this matter.
Please attach the useful link if you have.

0 Karma

somesoni2
Revered Legend

Running 53 realtime searches could be an overkill (realtime alerts never dies, keep occupying system resources, thus degrading overall system performance). I would suggest rather using a regular historical search, may be running very frequently, say every 5 min or so.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...