Hello, currently I have defined 9 Real Time Alerts in my Splunk System
The problem is that only 8 of them "can" trigger depending which of them I "activate"
If I activate all 9 of them, the last one which got activated will not trigger..
how to overcome this issue?
best regards
Each real-time query/alert, requires a CPU core to run, so just be sure you have enough resources to run all real time querys. In my personal opinion, 9 RT alerts are a lot. It would be much better to run all of them every minute or something like that
according to splunk documentation it is better to use real time alerts, rather than scheduled alerts every minute..