Splunk Search

Alerts not Finalizing- Is there a way to find out why it's getting stuck?

alucarddjin
Path Finder

I've got an issue with a scheduled alert that keeps going to finalizing but never stops (if this happens on the weekend it will "finalize" all weekend until I kill it on Monday).

Is there a way to find out why it's getting stuck, or to set a finalizing time limit so it just stops after n seconds regardless of state?

I've already set the dispatch.max_time but that doesn't appear to effect the finalizing duration.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...