Hello, In splunk Enterprise Has anyone experienced cases where notable events are generated after 10+hrs the trigger time?
scenario is - I have created correlation searches which runs every 10mins . for adaptive responses i have configured email alert and notable. Although email alerts get triggered properly as per schedule but the notables are getting generated 10-12hrs past the alert triggered time.
Can anyone suggest on how to proceed on troubleshooting this ?
figured out the issue. the _time field was converted to string value which caused the notable to be generated at GMT time rather than sydney time .
removed the string convertion
figured out the issue. the _time field was converted to string value which caused the notable to be generated at GMT time rather than sydney time .
removed the string convertion