Alerting

why RealTime Alert is not triggering ?

ajitshukla61116
Path Finder

can anybody tell me what are the capability required to search and trigger the realtime alert.
When I configured realtime alert with admin account its working fine but when it`s configured with normal user account its not working.

My scheduled alert working fine with normal user account .

please tell me what could be the reason for this .

0 Karma

woodcock
Esteemed Legend

Most admins deliberately disable all realtime capabilities because these searches are so horrifically detrimental to the Search Head.

0 Karma

vishaltaneja070
Motivator

Hello @ajitshukla61116

You need to assign user schedule_rtsearch capability
Please find the below link which can give you better idea:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Rolesandcapabilities
0 Karma

ajitshukla61116
Path Finder

already assigned schedule_rtsearch but still I am not able to get real time alert.

0 Karma

vishaltaneja070
Motivator

@ajitshukla

Can you please check the internal logs and see if they are getting spiked because of hardware restrictions.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...