Alerting

Splunk scheduler logs missing for all alerts

vrmandadi
Builder

We have alerts running and sending an alert to service now or to mail .We did not get the alerts last saturday and sunday and when I went into internal logs and searched for the saved searches events I dont see any events.Below is the search i used.I can see events before and after the weekend but not on saturday and sunday

index=_internal sourcetype=scheduler saved_searchname= *

Any thoughts or did any one ran into these kind of issue

0 Karma

burwell
SplunkTrust
SplunkTrust

Hello @vrmandadi Can you share the schedule you run the alerts on?

0 Karma

vrmandadi
Builder

There are multiple alerts running at different times.Some run every 5 minutes ,some every 10 mins,some every 15 mins,some every 30 mins ...etc

0 Karma

vrmandadi
Builder

Any one had the same issue?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Note: This post outlines a proposed architecture and serves as an interest check. If we secure commitments ...