Alerting

Why am I receiving frequent alerts from DMC?

thahir
Communicator

Hi Team,

I am getting very frequent alert for one of my search peer from DMC even though search head is up and working fine and i have analyzed the logs but i could not find anything abnormal in the logs except script runner error.  Can you please assist me on this issue

Labels (1)
0 Karma

thahir
Communicator

Hi @gcusello , triggering conditions are fine. Its a false alert right. I have validated in the server end and services are not down its up and running fine without any issues.. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

you can be sure that if the alert triggers, there's a momentary state when the condition is matched, so you have to debug this condition and find it, then you have to modify your alert's search to avoid this condition.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

if you're speaking of a DMC Alert, you could see in the DMC Alerts what are the triggering conditions of that alert anche you could disable this alert or change the triggering conditions.

E.g. there are some alerts that check when a script has an exit code different than 1, you can solve modifying the script indicated by the alert message or disabling the alert.

Are yousure that's a DMC Alert?

Have you ES?

Ciao.

Giuseppe

0 Karma

thahir
Communicator

Hi @gcusello , its same conditions for all other search peers. I am getting alert for only one search head frequently from DMC

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

as I said, identify the alert, open it and see the triggering conditions.

then you can modify or disable it.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...