Alerting

Basic alert not triggering

ofirbs
New Member

Hi,

I have 2 Splunk servers with the same alert on both of them.
One is triggering the alert and the other one is not.

Even by configuring the most basic alert search :

|noop|stats count|eval count = count + 1

which returns 1 line with count 1

  • "Add to triggered alerts" is configured
  • alert is running every minute with cron.
  • number of results is greater than 0

One of them triggers and the other won't even though they are the same, so I think that there is something else outside the alert configuration.

What can I verify?

Thanks.

0 Karma

woodcock
Esteemed Legend

In later versions of Splunk (not sure when it changed), you have to use the Add Actions button and select the Add to Triggered Alerts alert action. Perhaps one of your Search Heads is an older version of Splunk or perhaps it is configured in such a way that this action is always auto-added. In any case, you should be able to manually add this to the ones that don't have it.

0 Karma

Richfez
SplunkTrust
SplunkTrust

By the alert not trigger, what exactly do you mean? If you look at jobs, does it show up there? Or just that, say, it won't send you an email? Because for the latter I'd check for differences in email setup between the two, AND check that whatever you are relaying through has allowed both servers to do this.

0 Karma

ofirbs
New Member

I mean that I don't see it in Activity -> Triggered Alerts, and neither in the bottom of the page of the alert where it says "There are no fired events for this alert."

The other alert does appear on both the places though on the second Splunk.

0 Karma

burwell
SplunkTrust
SplunkTrust

How about in the job history?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...