Splunk On-Call

How to change alert so that When no one is on-call, notify the next person that starts a shift?


Hi, we currently have one of our on-call schedules to be office hours only (Weekdays 9-5). However, we are noticing that we don't get notified about alerts that get raised over the weekend. Our expectation was that with these alerts, because no one is there to acknowledge them, they will still be there when someone is eventually on the roster at 9am Monday but apparently that is not the case. (The alert is in the list of alerts, but it doesn't page anyone). 

Is there a way to ensure that the person that gets rostered on at 9am Monday will be notified of any alerts that were triggered over the preceding weekend (period where no one was on-call)? 


Labels (1)
Tags (2)
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...