Alerting

Restarting Splunk triggers all my alerts (and floods my inbox)

nickhills
Ultra Champion

I have a number of scheduled alerts which have thresholds configured to send me alerts if we see either too many or too few events in a given timeframe. But a restart of my seachhead triggers each of these events to fire (despite, it would seem the threshold not being crossed).

Is there anyway to prevent these alerts firing when restarting spunk, i.e. delay an alert triggering immediatly following startup.

I can't be the only person to find this irritating 🙂

If my comment helps, please give it a thumbs up!
Tags (2)

nickhills
Ultra Champion

Charles,

Did you ever get a response from your support case? This still plagues us.

If my comment helps, please give it a thumbs up!
0 Karma

andyfry_nec
Engager

me too.

Did anyone open a support case?

0 Karma

sf_user_199
Path Finder

I have a similar problem - we have real time alerts that trip when there is a lack of certain items present. If there is a brief interruption in communication from the search head to indexers, the alert trips.

0 Karma

charles_colvin
Explorer

Yes, I opened a case. Actually my issue is that when I edit or disable a realtime search, the search triggers. I suspect the two issues are related. I'll post whatever solution I get from support.

0 Karma

charles_colvin
Explorer

I have also experienced this issue. I guess it's time to open a support case...

0 Karma

nickhills
Ultra Champion

This is still very much a problem in our estate.

Can anyone else confirm that they see the same behaviour?

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...