Alerting

Why am I receiving frequent alerts from DMC?

thahir
Path Finder

Hi Team,

I am getting very frequent alert for one of my search peer from DMC even though search head is up and working fine and i have analyzed the logs but i could not find anything abnormal in the logs except script runner error.  Can you please assist me on this issue

Labels (2)
0 Karma

thahir
Path Finder

Hi @gcusello , triggering conditions are fine. Its a false alert right. I have validated in the server end and services are not down its up and running fine without any issues.. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

you can be sure that if the alert triggers, there's a momentary state when the condition is matched, so you have to debug this condition and find it, then you have to modify your alert's search to avoid this condition.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

if you're speaking of a DMC Alert, you could see in the DMC Alerts what are the triggering conditions of that alert anche you could disable this alert or change the triggering conditions.

E.g. there are some alerts that check when a script has an exit code different than 1, you can solve modifying the script indicated by the alert message or disabling the alert.

Are yousure that's a DMC Alert?

Have you ES?

Ciao.

Giuseppe

0 Karma

thahir
Path Finder

Hi @gcusello , its same conditions for all other search peers. I am getting alert for only one search head frequently from DMC

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

as I said, identify the alert, open it and see the triggering conditions.

then you can modify or disable it.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...