Alerting

Why am I receiving frequent alerts from DMC?

thahir
Communicator

Hi Team,

I am getting very frequent alert for one of my search peer from DMC even though search head is up and working fine and i have analyzed the logs but i could not find anything abnormal in the logs except script runner error.  Can you please assist me on this issue

Labels (1)
0 Karma

thahir
Communicator

Hi @gcusello , triggering conditions are fine. Its a false alert right. I have validated in the server end and services are not down its up and running fine without any issues.. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

you can be sure that if the alert triggers, there's a momentary state when the condition is matched, so you have to debug this condition and find it, then you have to modify your alert's search to avoid this condition.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

if you're speaking of a DMC Alert, you could see in the DMC Alerts what are the triggering conditions of that alert anche you could disable this alert or change the triggering conditions.

E.g. there are some alerts that check when a script has an exit code different than 1, you can solve modifying the script indicated by the alert message or disabling the alert.

Are yousure that's a DMC Alert?

Have you ES?

Ciao.

Giuseppe

0 Karma

thahir
Communicator

Hi @gcusello , its same conditions for all other search peers. I am getting alert for only one search head frequently from DMC

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thahir,

as I said, identify the alert, open it and see the triggering conditions.

then you can modify or disable it.

Ciao.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...