Alerting

why RealTime Alert is not triggering ?

ajitshukla61116
Path Finder

can anybody tell me what are the capability required to search and trigger the realtime alert.
When I configured realtime alert with admin account its working fine but when it`s configured with normal user account its not working.

My scheduled alert working fine with normal user account .

please tell me what could be the reason for this .

0 Karma

woodcock
Esteemed Legend

Most admins deliberately disable all realtime capabilities because these searches are so horrifically detrimental to the Search Head.

0 Karma

vishaltaneja070
Motivator

Hello @ajitshukla61116

You need to assign user schedule_rtsearch capability
Please find the below link which can give you better idea:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Rolesandcapabilities
0 Karma

ajitshukla61116
Path Finder

already assigned schedule_rtsearch but still I am not able to get real time alert.

0 Karma

vishaltaneja070
Motivator

@ajitshukla

Can you please check the internal logs and see if they are getting spiked because of hardware restrictions.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...