Alerting

Rerun an alert until it gets the result of more than 0

drubench
Observer

Hi,

Is there a way to rerun an alert until it gets the result of more than 0?

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The alert is scheduled so it will be re-run automatically at the scheduled time.  There is no way, AFAIK, to stop the alert automatically once it finds a result.  What problem are you trying to solve?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...