I want to create an email alert based on my search results. But i am receiving email alert after almost 8 hours. What might be the reason?
I have set the real time alert for this and the time given is rt-2m to rt-0m and throttled it for 4 hrs.
I wrote an answer about real-time alerts recently: https://answers.splunk.com/answers/684144/how-to-stop-a-single-account-email-alert-to-trigge.html#an...
Basically I don't recommend using real-time alerts. You can schedule for -2m to now and your indexers won't be as taxed.