Reporting

Alerts Failing to Trigger v7.1.1

KevinLamMCD
Engager

Hi I'm trying to set up a basic alert to trigger whenever a Host search generates new results, the corresponding alert action is an email.

The host is constantly generating new data and when a normal search is conducted, new data can be seen being ingested. So its very obvious that data exists and that Splunk sees the data. But when i save the search as an alert that is supposed to trigger "per-result", so theoretically it should be going off constantly- yet nothing is being triggered (confirmed within the trigger alerts being empty). Additionally, emails are never generated.

Tags (3)
0 Karma

gjanders
SplunkTrust
SplunkTrust

There were some bugs in alert actions that were supposed to have been fixed in 7.1.2, 7.1.2 is out now perhaps try that version?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...