Alerting

How do I create an email alert based on the following search results?

Yogesh7867
Engager

I want to create an email alert based on my search results. But i am receiving email alert after almost 8 hours. What might be the reason?

I have set the real time alert for this and the time given is rt-2m to rt-0m and throttled it for 4 hrs.

0 Karma

burwell
SplunkTrust
SplunkTrust

I wrote an answer about real-time alerts recently: https://answers.splunk.com/answers/684144/how-to-stop-a-single-account-email-alert-to-trigge.html#an...

Basically I don't recommend using real-time alerts. You can schedule for -2m to now and your indexers won't be as taxed.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...