Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

Alerts in Splunk Incidents

vijreddy30
Loves-to-Learn Everything

Hi team 

 

Created the Customize field in Splunk Alert mechanism, but in the incident receiving the single record only , Multiple records are not fetching the incident, please find the below  

 

location=KC xxxxxxxx Corporate Center||comments=Look into VPR Quality Docs Notifications Outlook email for Actual errors||description=Login to VPR Server and Quality Docs Vault to troubleshoot issue;
$result._time$ $result.host$ $result.Message$ $result.source$ $result.log_level$ $result.error_message$

 

Please help me 

0 Karma

tej57
Builder

Hello @vijreddy30 ,

This may be possible because of following setting in the alert: Trigger

tej57_0-1717766038019.png

 

If this is set to Once, change it to "For each Result" and it should trigger alert for all the records.

Thanks,
Tejas.

 

---

If the above solution helps, an upvote is appreciated.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...