All Apps and Add-ons

Why would alerts show in "KPI Report - Incident Status" report as long runners, but not show up on incident posture page?

joshua_hart1
Path Finder

Occasionally, alerts will fire that seem to get stuck and never make it into the Incident Posture dashboard. When I check the Incident Status KPI dashboard, they show up in the Long Runners but searching for the incident id yields no results. Please advise. Thanks!

-Josh

Tags (1)
0 Karma

my2ndhead
SplunkTrust
SplunkTrust

I suspect, that some large events created as "index=alerts sourcetype=alert_metadata" may get truncated.

There's a bugfixes version of TA-alert_manager you could try out:

https://github.com/alertmanager/TA-alert_manager/tree/develop

Download as a zip file, and rename the directory to TA-alert_manager

0 Karma

joshua_hart1
Path Finder

Thanks, I'll give that a try and report back.

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...