Suddenly the real-time alert is not working for Splunk, can anyone help on this how to troubleshoot this issue
I'm sure there's *someone* here who can help, but they will need some help from you first.
What exactly do you mean by "is not working" (that phrase should be banned here, IMO)? What is it (not) doing? How is the current behavior different from previous behavior?
When did the behavior change? What other changes happened around the same time?
Is there anything in search.log for the alerts that might explain the change in behavior?