Alerting

How to change Alert type

chensteven
New Member

Hello,

On Splunk cloud dashboard alert setup, how I can setup the alert email to be sent as soon as the incident occurs? is it possible change the "Alert type" from Scheduled to other type? All I can do seems to be setup a schedule only. Please help. Thank you.

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Alerts go out as soon as the incident is detected. How long that takes depends on how long it takes for the incident to make its way into Splunk and also on how often the alert runs. Plus there's the latency in delivering the alert email.

I think your best option is to make the alert run more often, as long as it is able to complete before the next run time.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...