Alerting

Splunk Alert False Positives

adzg
Engager

I have an alert that runs every 10 minutes from 6am-3pm PST.  It checks to see if a file has arrived within the last few minutes (file arrives at 6:10, check for file at 6:12 with 4 minute timeframe). 

The problem is that every day, I get 1-3 false positive alerts.  I get an email saying that a file didn't arrive on time but when I go to perform the exact search with the hardcoded timeframe in question, the file did arrive on time. 

Anyone ever run into this problem? Is this an issue with the alert scheduler?  I tried moving the alert back to give the file time to process in the system (file arrives at 6:10, check for file at 6:15 with 8 minute timeframe) but to no avail.

Labels (3)
0 Karma

SinghK
Builder

set it up at 6: 15 and let it check for last 10 min

0 Karma

adzg
Engager

How would that be practically different than what I've already tried, which is 6:15 looking back 8 minutes?  The file always arrives at XX:10:05

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>