Alerting

Search Head Cluster : Duplicate alert action

andrei1bc
Communicator

Hi,

I have a search head cluster with 3 members, that connects to an index cluster of 10 members. Both clusters are running version 7.0 with no replication or performance issues. The search head cluster has an additional alert action installed on all nodes, that performs an API call to an external system.

Whenever an alert is triggered, the action is executed by 2 of the search head cluster members, generating duplicate API calls.

Please assist and thanks in advance.

Regards,
Bogdan

0 Karma

somesoni2
Revered Legend

Check scheduler logs (index=_internal sourcetype=scheduler) for your alert search to see if the first invocation was completed successfully or not (I believe it should have an event with status=delegated_remote_completion or something). It it was not, they the captain might have assumed it was not completed and fired it again.

0 Karma

PowerPacked
Builder

Hi @andrei1bc

as somesoni2, mentioned you can look into index=_internal sourcetype=scheduler savedsearch_name=yoursearchname status=success/skipped/delegated/delgated_remote_error/delgated_remote_completion to analyze why its running twice

& also you can look into
index=_introspection sourcetype=splunk_resource_usage component=PerProcess data.process=splunkd data.process_type=search ------- search_props section will list out on what search head the search is running and many other things.

Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...