Reporting

Alerts Failing to Trigger v7.1.1

KevinLamMCD
Engager

Hi I'm trying to set up a basic alert to trigger whenever a Host search generates new results, the corresponding alert action is an email.

The host is constantly generating new data and when a normal search is conducted, new data can be seen being ingested. So its very obvious that data exists and that Splunk sees the data. But when i save the search as an alert that is supposed to trigger "per-result", so theoretically it should be going off constantly- yet nothing is being triggered (confirmed within the trigger alerts being empty). Additionally, emails are never generated.

Tags (3)
0 Karma

gjanders
SplunkTrust
SplunkTrust

There were some bugs in alert actions that were supposed to have been fixed in 7.1.2, 7.1.2 is out now perhaps try that version?

0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...