Alerting

Why are there no results/unknown sid when set to real time alerts?

vetri
New Member

I have my splunk integrated with snow addon for incident creation, when set to real time receiving unknown sid in the alerts history and no tickets are getting generated but when set to 1 min scheduled window it's working fine with no issues.

could someone help me to understand what's the issue here please.

Labels (1)
0 Karma

c82507b
Engager

Hi colleague , Iam having this issue , were you able to resolve it?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...