Alerting

Real time alerts

christinmb
Path Finder

Im having problems with the real time alerts, splunk is not sending all the events by email, it works fine in the first 3 minuts, but after that Im not getting any email or events in the alert manager, but if i schedule that same search but dont make it rt search it does work and I get all my alerts in my inbox.
This problem started after I upgrade to Splunk 5, with Splunk 4.x I didnt have that problem

0 Karma
1 Solution

BobDaMann
Explorer

Could you provide more information? I'd like to know a little bit more about the alert you have set up.

Perhaps a screenshot of the alert settings?

Are you using throttling?

View solution in original post

BobDaMann
Explorer

Awesome. Well I am glad I was able to help. Take it easy.

0 Karma

BobDaMann
Explorer

Could you provide more information? I'd like to know a little bit more about the alert you have set up.

Perhaps a screenshot of the alert settings?

Are you using throttling?

View solution in original post

christinmb
Path Finder

It was an error in the "per results throttling fields" and the alerting mode, thanks!

0 Karma

christinmb
Path Finder

https://dl.dropbox.com/u/97076067/df.png thats the configuration I have

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!