Alerting

realtime alerts - exactly one alert per event ?

elenzil
Path Finder

i would like to set up a realtime alert which fires exactly once per matching search.
throttling is close to this, but not exactly.
eg, if i have two events in a sub-second window,
i want two alerts.

in the meantime, even with throttling, i'm finding myself getting > 1 alert per event.

is there something i'm missing ?

tia,
orion

Tags (3)
0 Karma
1 Solution

Takajian
Builder

I do not think real time alert function is able to fire alert per each events. I heard next version 4.3 will have some improvment of real time alert functions.

View solution in original post

0 Karma

Takajian
Builder

I do not think real time alert function is able to fire alert per each events. I heard next version 4.3 will have some improvment of real time alert functions.

0 Karma

AditiKulkarni
New Member

Can we achieve this condition in Splunk 6.1.5?

0 Karma

elenzil
Path Finder

😕

thanks Takajian. i guess i'll approximate it w/ threshholds.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...