Alerting

Real time alerts

christinmb
Path Finder

Im having problems with the real time alerts, splunk is not sending all the events by email, it works fine in the first 3 minuts, but after that Im not getting any email or events in the alert manager, but if i schedule that same search but dont make it rt search it does work and I get all my alerts in my inbox.
This problem started after I upgrade to Splunk 5, with Splunk 4.x I didnt have that problem

0 Karma
1 Solution

BobDaMann
Explorer

Could you provide more information? I'd like to know a little bit more about the alert you have set up.

Perhaps a screenshot of the alert settings?

Are you using throttling?

View solution in original post

BobDaMann
Explorer

Awesome. Well I am glad I was able to help. Take it easy.

0 Karma

BobDaMann
Explorer

Could you provide more information? I'd like to know a little bit more about the alert you have set up.

Perhaps a screenshot of the alert settings?

Are you using throttling?

christinmb
Path Finder

It was an error in the "per results throttling fields" and the alerting mode, thanks!

0 Karma

christinmb
Path Finder

https://dl.dropbox.com/u/97076067/df.png thats the configuration I have

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...