Alerting

maximum number of alerts?

ESIMatNeforce
Path Finder

Hello, currently I have defined 9 Real Time Alerts in my Splunk System
The problem is that only 8 of them "can" trigger depending which of them I "activate"
If I activate all 9 of them, the last one which got activated will not trigger..

how to overcome this issue?

best regards
ESIMatNeforce

Tags (4)
0 Karma

gfuente
Motivator

Hello

Each real-time query/alert, requires a CPU core to run, so just be sure you have enough resources to run all real time querys. In my personal opinion, 9 RT alerts are a lot. It would be much better to run all of them every minute or something like that

Regards

0 Karma

ESIMatNeforce
Path Finder

according to splunk documentation it is better to use real time alerts, rather than scheduled alerts every minute..
regards

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...