I have configured an Alert that is running in real time.
with the value of host="10.56.183.0" "%LINEPROTO-5-UPDOWN"
since 10.56.183.0 is a switch and I'd like to recieve an email when interface goes up or down.
When the event occurs once (I can see in the search that it ocurrs once) I'm getting 2 emails.
and when looking at the Alert window - I can see that it counted 2.
any idea why ?
Hi @dschnabel,
Could you share more of your alert configuration? For example, what do you have for the query, the triggering condition, and any throttling? Also, what software version are you using?
Thanks for the details!
Hi @frobinson,
thanks for your reply. This is the configuration of my alert:
Query: index=tv-* ClientId NOT (some-id-1 OR some-id-2 OR some-id-3) ClientId="*" Class NOT SUCCESS_FIRST_ATTEMPT NOT "Server did not accept key" Mode=Installation
Trigger Condition: Per-Result
Alert Type: Real-time
No throttling.
Where would I find the software version?
Daniel
Hi Daniel,
You can try the "About" link at bottom-left of a page in Splunk Web:
http://docs.splunk.com/Documentation/Splunk/6.3.1511/Troubleshooting/CheckSplunkversion
Splunk Version 6.3.1511.1
Splunk Build 90ea9ab275dc
List of Products: retention
Server Name ip-192-168-92-140
[...]
Current Application: Search & Reporting
App Version 6.3.1511.1
Thanks for the version info! Please see my comment below--I think throttling could help reduce the triggering.