Dashboards & Visualizations

Splunk Alert Triggers after 15 minutes of its scheduled time

AniketD
New Member

Hi All,

I've configured an alert which sends a mail when the count is not less than 1 for a particular feed.

I;ve given the below criteria :

Cron Schedule : 45 21 asterisk asterisk 0 [ So that is runs at 21:45 on every Sunday, I;ve written asterisk as the symbol was not coming in the post ]
Time Range : Earliest [-15m@m] Latest [@m] , so that it checks if the count is not less than 1 at 21:45 for the last 15 minutes

The problem here is that the search triggers at nearly 21:59 , however, the time range picked remains the same [21:30 - 21:45 ] and I get a email at around 10:01

can someone please tell me what is happening and is there anything which I am missing and need to know and understand

0 Karma

tiagofbmm
Influencer
0 Karma

FeatureCreeep
Path Finder

Have you checked your job in the Activities view? That will tell you what time the job executed and how long it took to complete. One possibility, There are alert options that allow your query to delay when it is ran if the Splunk cluster is busy so maybe you selected one of those options? Another possibility is that the query just took that long to complete. I'm guessing that isn't the case but looking at the job from the Activities view should help you narrow down the possible causes.

0 Karma

AniketD
New Member

Hi,

Thanks a lot for your response!

Yes, I did went into the activities view and it is from there I came to know that it ran after nearly 15 mins of it scheduled time. The query took about a minute to run.

To answer your 2nd question, no I did not select any such criteria/options to delay the alert.

One thing I observed even for other alerts is that the delay is about 15 min.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...