Hi,
Splunk started sending false alerts since today morning even though aler condition hasn't been triggsered. Once we re-enable alert those are working fine. 
Can anybody please help what could be the reason behind this as this is become severity one issue  in Splunk Production Environment?
Thanks in advance. 🙂
Any updates ?
Any recommendations on how to troubleshoot the issue of false alerts during the OS patching of the Splunk servers (Indexers/SearchHeads) ?
Can you please provide us more information. Is the alert configured as notable event. if that is the case ,you nee to check your throttling parameters
 
					
				
		
Get a better description, get a diag file, add the bug tag to this Question, and open a Support Case.
 
					
				
		
Which version of Splunk did it happen?
Splunk 6.4.0
Can somebody please help?
 
					
				
		
If it's severity 1 then I'll suggest to raise case with splunk support.
