Alerting

Real time alerts

christinmb
Path Finder

Im having problems with the real time alerts, splunk is not sending all the events by email, it works fine in the first 3 minuts, but after that Im not getting any email or events in the alert manager, but if i schedule that same search but dont make it rt search it does work and I get all my alerts in my inbox.
This problem started after I upgrade to Splunk 5, with Splunk 4.x I didnt have that problem

0 Karma
1 Solution

BobDaMann
Explorer

Could you provide more information? I'd like to know a little bit more about the alert you have set up.

Perhaps a screenshot of the alert settings?

Are you using throttling?

View solution in original post

BobDaMann
Explorer

Awesome. Well I am glad I was able to help. Take it easy.

0 Karma

BobDaMann
Explorer

Could you provide more information? I'd like to know a little bit more about the alert you have set up.

Perhaps a screenshot of the alert settings?

Are you using throttling?

christinmb
Path Finder

It was an error in the "per results throttling fields" and the alerting mode, thanks!

0 Karma

christinmb
Path Finder

https://dl.dropbox.com/u/97076067/df.png thats the configuration I have

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...