Monitoring Splunk

Alert

Amoreuser
New Member

Hello,

I just wanted to know more detailed information so I opened the case.

About Alert settings.

I set  Threshold '90' , Trigger 'Immediately'  and Alert when ' Above ' 

If the above settings are
Does the alarm occur from 90.1?

I remember in the beginning, if I set it to 90, it was registered as 89.

It's currently set up that way
I would like to know if an alert is occurring at 89.1.

In case an alarm occurs at 89.1,
I need to fix it as soon as possible

Please reply

 

Thank you !!!

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What product/service are you talking about? Splunk Enterprise doesn't have the settings you describe. Is it Observability?

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Hi @Amoreuser, Based on what you described, there seems to be an config issue in your alert setup. If your threshold is set to 90 but alerts are triggering at 89.1, you may want to check a few things: First, verify that your alert condition is exactly set to "Above" and not "Above or Equal". Second, take a look at your search query to make sure there's no unintended data processing affecting the values. If you're working with decimal values, you might want to add a round() function in your search to ensure more precise threshold control.

Could you share your search query so I can help identify the issue?





If this Helps, Please Upvote.

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...