Knowledge Management

Bug in alert condition when summary index enabled?

phoenixdigital
Builder

Hi All,

If you create a saved search in the web interface and then set the alert condition to 'if custom condition is met' then enter a custom condition search.

See second image here http://imgur.com/a/qIe8z

Then before pressing submit you tick enable to summary indexing. This resets the settings you made above.

See first image here http://imgur.com/a/qIe8z

I have tested this on two different instances of Splunk (5.0.2 and 5.0.1) and the bug exists on both versions.

Worse the issue also happens when you go back in to edit the search. Even when 'if custom condition is met' is set in the savedsearches.conf it will reset back if summary indexing is enabled. So if the user does not know about this bug they will lose their alert condition settings.

Are others seeing this with their versions of Splunk?

I have submitted this as a bug but was curious if others can reproduce?

Tags (1)

sloshburch
Ultra Champion

Would it work to use loadjob or savedsearch commands to pull up the recent run and conditionally alert upon that?

0 Karma

mpawar_splunk
Splunk Employee
Splunk Employee

This is not a bug but an expected behavior because summary indexing for an alert cannot be conditional.
If you want to use other alert conditions, you must disable summary indexing.

0 Karma

jrodriguezap
Contributor

No way to add the "if number of events" ???
It is very important to get this

jds123
Explorer

Although this is expected behavior, what if you are trying to have an email alert action and summary indexing in the same saved search? By forcing the "always" condition, emails alerts will trigger every time the search runs.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...