Alerting

Why is there a delay in custom alert firing?

Prakash493
Communicator

Hi

I have an issue i have an alert is running which invokes the custom script when it fires , but i have a 3 min delay , when i saw logs i find out the logs are ingesting on right time no delay in log ingestion , when the alert is running its showing right time but when it invoking the custom script their is a delay of 3 min ? any one can please help me ?

0 Karma

woodcock
Esteemed Legend

Make sure that ALL of your servers are using NTP. I assume that the problem is clock drift.

0 Karma

Prakash493
Communicator

No its not real time , Thanks i will check if it uses NTP or not ?

Thanks

0 Karma

woodcock
Esteemed Legend

You are not running a real-time search for this, are you?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...