Alerting

maximum number of alerts?

ESIMatNeforce
Path Finder

Hello, currently I have defined 9 Real Time Alerts in my Splunk System
The problem is that only 8 of them "can" trigger depending which of them I "activate"
If I activate all 9 of them, the last one which got activated will not trigger..

how to overcome this issue?

best regards
ESIMatNeforce

Tags (4)
0 Karma

gfuente
Motivator

Hello

Each real-time query/alert, requires a CPU core to run, so just be sure you have enough resources to run all real time querys. In my personal opinion, 9 RT alerts are a lot. It would be much better to run all of them every minute or something like that

Regards

0 Karma

ESIMatNeforce
Path Finder

according to splunk documentation it is better to use real time alerts, rather than scheduled alerts every minute..
regards

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...