can anybody tell me what are the capability required to search and trigger the realtime alert.
When I configured realtime alert with admin account its working fine but when it`s configured with normal user account its not working.
My scheduled alert working fine with normal user account .
please tell me what could be the reason for this .
Most admins deliberately disable all realtime
capabilities because these searches are so horrifically detrimental to the Search Head.
Hello @ajitshukla61116
You need to assign user schedule_rtsearch capability
Please find the below link which can give you better idea:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Rolesandcapabilities
already assigned schedule_rtsearch but still I am not able to get real time alert.
@ajitshukla
Can you please check the internal logs and see if they are getting spiked because of hardware restrictions.