Alerting

why RealTime Alert is not triggering ?

Path Finder

can anybody tell me what are the capability required to search and trigger the realtime alert.
When I configured realtime alert with admin account its working fine but when it`s configured with normal user account its not working.

My scheduled alert working fine with normal user account .

please tell me what could be the reason for this .

0 Karma

Esteemed Legend

Most admins deliberately disable all realtime capabilities because these searches are so horrifically detrimental to the Search Head.

0 Karma

Motivator

Hello @ajitshukla61116

You need to assign user schedule_rtsearch capability
Please find the below link which can give you better idea:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Rolesandcapabilities
0 Karma

Path Finder

already assigned schedule_rtsearch but still I am not able to get real time alert.

0 Karma

Motivator

@ajitshukla

Can you please check the internal logs and see if they are getting spiked because of hardware restrictions.

0 Karma