Why are alerts not being triggered for all the events when trigger is set to "For Each Result"?

Splunk Employee
Splunk Employee

I have created a scheduled search of the type:

index=_internal | head 100

Now, I have kept the cron schedule, such that this search will execute every 5 minutes. And the trigger mode is "For Each Result". So, for 100 results, 100 alerts must be fired.

Now, the alerts are only triggered for 5 minutes. So, let's say for the scheduled search with sid=sid1 has executed 50 alerts for 50 events. After 5 minutes, search with sid2 is triggered. Now, the alerts for sid1 are stopped, and it will continue for sid2.

Is this known behaviour of Splunk? Can we change this?

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>