Alerting

Splunk Alert False Positives

adzg
Engager

I have an alert that runs every 10 minutes from 6am-3pm PST.  It checks to see if a file has arrived within the last few minutes (file arrives at 6:10, check for file at 6:12 with 4 minute timeframe). 

The problem is that every day, I get 1-3 false positive alerts.  I get an email saying that a file didn't arrive on time but when I go to perform the exact search with the hardcoded timeframe in question, the file did arrive on time. 

Anyone ever run into this problem? Is this an issue with the alert scheduler?  I tried moving the alert back to give the file time to process in the system (file arrives at 6:10, check for file at 6:15 with 8 minute timeframe) but to no avail.

Labels (3)
0 Karma

SinghK
Builder

set it up at 6: 15 and let it check for last 10 min

0 Karma

adzg
Engager

How would that be practically different than what I've already tried, which is 6:15 looking back 8 minutes?  The file always arrives at XX:10:05

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...