Hello, currently I have defined 9 Real Time Alerts in my Splunk System
The problem is that only 8 of them "can" trigger depending which of them I "activate"
If I activate all 9 of them, the last one which got activated will not trigger..
Each real-time query/alert, requires a CPU core to run, so just be sure you have enough resources to run all real time querys. In my personal opinion, 9 RT alerts are a lot. It would be much better to run all of them every minute or something like that