Alerting

Triggered Alerts are Occuring twice on every Event that happens once

sbeamro
Explorer

I have configured an Alert that is running in real time.
with the value of host="10.56.183.0" "%LINEPROTO-5-UPDOWN"
since 10.56.183.0 is a switch and I'd like to recieve an email when interface goes up or down.

When the event occurs once (I can see in the search that it ocurrs once) I'm getting 2 emails.
and when looking at the Alert window - I can see that it counted 2.

any idea why ?

Tags (1)
0 Karma

frobinson_splun
Splunk Employee
Splunk Employee

Hi @dschnabel,
Could you share more of your alert configuration? For example, what do you have for the query, the triggering condition, and any throttling? Also, what software version are you using?
Thanks for the details!

0 Karma

dschnabel
Explorer

Hi @frobinson,

thanks for your reply. This is the configuration of my alert:


Query: index=tv-* ClientId NOT (some-id-1 OR some-id-2 OR some-id-3) ClientId="*" Class NOT SUCCESS_FIRST_ATTEMPT NOT "Server did not accept key" Mode=Installation

Trigger Condition: Per-Result

Alert Type: Real-time

No throttling.


Where would I find the software version?

Daniel

frobinson_splun
Splunk Employee
Splunk Employee

Hi Daniel,
You can try the "About" link at bottom-left of a page in Splunk Web:
http://docs.splunk.com/Documentation/Splunk/6.3.1511/Troubleshooting/CheckSplunkversion

0 Karma

dschnabel
Explorer

Splunk Version 6.3.1511.1
Splunk Build 90ea9ab275dc
List of Products: retention
Server Name ip-192-168-92-140
[...]
Current Application: Search & Reporting
App Version 6.3.1511.1

frobinson_splun
Splunk Employee
Splunk Employee

Thanks for the version info! Please see my comment below--I think throttling could help reduce the triggering.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...