Reporting

Alerts Failing to Trigger v7.1.1

KevinLamMCD
Engager

Hi I'm trying to set up a basic alert to trigger whenever a Host search generates new results, the corresponding alert action is an email.

The host is constantly generating new data and when a normal search is conducted, new data can be seen being ingested. So its very obvious that data exists and that Splunk sees the data. But when i save the search as an alert that is supposed to trigger "per-result", so theoretically it should be going off constantly- yet nothing is being triggered (confirmed within the trigger alerts being empty). Additionally, emails are never generated.

Tags (3)
0 Karma

gjanders
SplunkTrust
SplunkTrust

There were some bugs in alert actions that were supposed to have been fixed in 7.1.2, 7.1.2 is out now perhaps try that version?

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...