Alerting

"AlertNotifier busy... Consider improving action execution speed or increase action_execution_threads in limits.conf" How to increase the limit?

lukasz92
Communicator

I have very large number (over hundred) of scheduled searches done every minute. Some have alert actions to send an email.

I get thousands of events like this:

WARN SavedSplunker - AlertNotifier busy! Failed to enqueue job for search_id="scheduler_(...)". No actions will be executed. Consider improving action execution speed or increase action_execution_threads in limits.conf

some thousands per day.

I raised this limit to 6 (and to 10 after) - and now I get about 0-100 per day.

How to cope with that? Documentation says, that 10 is the maximum. I want to disable this limit at all.

0 Karma

Masa
Splunk Employee
Splunk Employee

There is no way to make it unlimited. Good practice is to use more search heads with SHC to distribute alerts and increase actions_queue_size (500 or so? ) Any unlimited settings need to be careful. It could use up all available resources.

0 Karma

lukasz92
Communicator

There are 4 searchheads in cluster now.

Thank you for this setting - I will try it.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...