Alerting

Why am I receiving frequent alerts from DMC?

thahir
Path Finder

Hi Team,

I am getting very frequent alert for one of my search peer from DMC even though search head is up and working fine and i have analyzed the logs but i could not find anything abnormal in the logs except script runner error.  Can you please assist me on this issue

Labels (2)
0 Karma

thahir
Path Finder

Hi @gcusello , triggering conditions are fine. Its a false alert right. I have validated in the server end and services are not down its up and running fine without any issues.. 

0 Karma

gcusello
Esteemed Legend

Hi @thahir,

you can be sure that if the alert triggers, there's a momentary state when the condition is matched, so you have to debug this condition and find it, then you have to modify your alert's search to avoid this condition.

Ciao.

Giuseppe

0 Karma

gcusello
Esteemed Legend

Hi @thahir,

if you're speaking of a DMC Alert, you could see in the DMC Alerts what are the triggering conditions of that alert anche you could disable this alert or change the triggering conditions.

E.g. there are some alerts that check when a script has an exit code different than 1, you can solve modifying the script indicated by the alert message or disabling the alert.

Are yousure that's a DMC Alert?

Have you ES?

Ciao.

Giuseppe

0 Karma

thahir
Path Finder

Hi @gcusello , its same conditions for all other search peers. I am getting alert for only one search head frequently from DMC

0 Karma

gcusello
Esteemed Legend

Hi @thahir,

as I said, identify the alert, open it and see the triggering conditions.

then you can modify or disable it.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...