Alerting

why RealTime Alert is not triggering ?

ajitshukla61116
Path Finder

can anybody tell me what are the capability required to search and trigger the realtime alert.
When I configured realtime alert with admin account its working fine but when it`s configured with normal user account its not working.

My scheduled alert working fine with normal user account .

please tell me what could be the reason for this .

0 Karma

woodcock
Esteemed Legend

Most admins deliberately disable all realtime capabilities because these searches are so horrifically detrimental to the Search Head.

0 Karma

vishaltaneja070
Motivator

Hello @ajitshukla61116

You need to assign user schedule_rtsearch capability
Please find the below link which can give you better idea:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Rolesandcapabilities
0 Karma

ajitshukla61116
Path Finder

already assigned schedule_rtsearch but still I am not able to get real time alert.

0 Karma

vishaltaneja070
Motivator

@ajitshukla

Can you please check the internal logs and see if they are getting spiked because of hardware restrictions.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...