Alerting

How can I change the time frame for real-time alerts?

ArsenyKapralov
Path Finder

Hi

I have a stream of events coming continuously, but with lag from the source which varies from 5 to 15 mins.
I want to run real-time searches based on these events, so I use rt-15m. But after search, I need to send email alerts based on search results. Problem is that in alerting settings, I can't set rt-15m, only rt.

How can I set up alerts to run in earliest=rt-30m latest=rt-15m time frame?

0 Karma

somesoni2
Revered Legend

The fixed latest time range value for any real-time search is "now", so it has to be rt only.(that way only it can have a sliding window for past so and so period). For your case, the lag varies from 5 to 15 mins and if you just use the rt-30m to rt, you should get all the events anyways.

Also, consider using a regular search running more frequenly as the real-time searches are expensive and should be avoided, if possible.
alt text

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...