Alerting

"AlertNotifier busy... Consider improving action execution speed or increase action_execution_threads in limits.conf" How to increase the limit?

lukasz92
Communicator

I have very large number (over hundred) of scheduled searches done every minute. Some have alert actions to send an email.

I get thousands of events like this:

WARN SavedSplunker - AlertNotifier busy! Failed to enqueue job for search_id="scheduler_(...)". No actions will be executed. Consider improving action execution speed or increase action_execution_threads in limits.conf

some thousands per day.

I raised this limit to 6 (and to 10 after) - and now I get about 0-100 per day.

How to cope with that? Documentation says, that 10 is the maximum. I want to disable this limit at all.

0 Karma

Masa
Splunk Employee
Splunk Employee

There is no way to make it unlimited. Good practice is to use more search heads with SHC to distribute alerts and increase actions_queue_size (500 or so? ) Any unlimited settings need to be careful. It could use up all available resources.

0 Karma

lukasz92
Communicator

There are 4 searchheads in cluster now.

Thank you for this setting - I will try it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...