Alerting

Scheduled Real-time AlertsTerminating

marksnelling
Communicator

I have a number of real-time alerts scheduled that prior to upgrading to Splunk 6.1 would run continuously. Since the upgrade these jobs now stop alerting even though the jobs are visible in the Activity/Jobs window and are in status "Running 100%".

To get the jobs to start alerting again I have to either delete and recreate them.

Is this a known issue or have I missed a breaking change somewhere in the upgrade?

1 Solution

piebob
Splunk Employee
Splunk Employee

this is appears to be a known issue in 6.1.1:
"After upgrading to 6.1 or 6.1.1, real-time searches (per-result or rolling window) may stop triggering alerts for matching events after running for more than 1 hour. Typically, this is noticed when these searches fail to trigger actions such as sending an email. (SPL-84357)"

http://docs.splunk.com/Documentation/Splunk/6.1.1/ReleaseNotes/KnownIssues

View solution in original post

piebob
Splunk Employee
Splunk Employee

this is appears to be a known issue in 6.1.1:
"After upgrading to 6.1 or 6.1.1, real-time searches (per-result or rolling window) may stop triggering alerts for matching events after running for more than 1 hour. Typically, this is noticed when these searches fail to trigger actions such as sending an email. (SPL-84357)"

http://docs.splunk.com/Documentation/Splunk/6.1.1/ReleaseNotes/KnownIssues

rainhailrob
Path Finder

I've noticed the same problem. We just upgraded from 6.03 to 6.1.1. We have 7 realtime jobs so I wouldn't think that would overload the system.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...