Alerting

realtime alerts - exactly one alert per event ?

elenzil
Path Finder

i would like to set up a realtime alert which fires exactly once per matching search.
throttling is close to this, but not exactly.
eg, if i have two events in a sub-second window,
i want two alerts.

in the meantime, even with throttling, i'm finding myself getting > 1 alert per event.

is there something i'm missing ?

tia,
orion

Tags (3)
0 Karma
1 Solution

Takajian
Builder

I do not think real time alert function is able to fire alert per each events. I heard next version 4.3 will have some improvment of real time alert functions.

View solution in original post

0 Karma

Takajian
Builder

I do not think real time alert function is able to fire alert per each events. I heard next version 4.3 will have some improvment of real time alert functions.

0 Karma

AditiKulkarni
New Member

Can we achieve this condition in Splunk 6.1.5?

0 Karma

elenzil
Path Finder

😕

thanks Takajian. i guess i'll approximate it w/ threshholds.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...