Alerting

why RealTime Alert is not triggering ?

ajitshukla61116
Path Finder

can anybody tell me what are the capability required to search and trigger the realtime alert.
When I configured realtime alert with admin account its working fine but when it`s configured with normal user account its not working.

My scheduled alert working fine with normal user account .

please tell me what could be the reason for this .

0 Karma

woodcock
Esteemed Legend

Most admins deliberately disable all realtime capabilities because these searches are so horrifically detrimental to the Search Head.

0 Karma

vishaltaneja070
Motivator

Hello @ajitshukla61116

You need to assign user schedule_rtsearch capability
Please find the below link which can give you better idea:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Rolesandcapabilities
0 Karma

ajitshukla61116
Path Finder

already assigned schedule_rtsearch but still I am not able to get real time alert.

0 Karma

vishaltaneja070
Motivator

@ajitshukla

Can you please check the internal logs and see if they are getting spiked because of hardware restrictions.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...