Alerting

Why am I receiving frequent alerts from DMC?

thahir
Path Finder

Hi Team,

I am getting very frequent alert for one of my search peer from DMC even though search head is up and working fine and i have analyzed the logs but i could not find anything abnormal in the logs except script runner error.  Can you please assist me on this issue

Labels (2)
0 Karma

thahir
Path Finder

Hi @gcusello , triggering conditions are fine. Its a false alert right. I have validated in the server end and services are not down its up and running fine without any issues.. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

you can be sure that if the alert triggers, there's a momentary state when the condition is matched, so you have to debug this condition and find it, then you have to modify your alert's search to avoid this condition.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

if you're speaking of a DMC Alert, you could see in the DMC Alerts what are the triggering conditions of that alert anche you could disable this alert or change the triggering conditions.

E.g. there are some alerts that check when a script has an exit code different than 1, you can solve modifying the script indicated by the alert message or disabling the alert.

Are yousure that's a DMC Alert?

Have you ES?

Ciao.

Giuseppe

0 Karma

thahir
Path Finder

Hi @gcusello , its same conditions for all other search peers. I am getting alert for only one search head frequently from DMC

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

as I said, identify the alert, open it and see the triggering conditions.

then you can modify or disable it.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...