Alerting

Alerts not triggering, but the same search has results

bazcurtis178
Explorer

Hi,

I have 6 Alerts that run on a schedule. Only one of them is working. If I run the search results come back that match. Why would they not be triggering?

 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @bazcurtis178,

did you tested the searches without results in the same time period or after when you checked it?

Please try to run it in the same time period of the schedules alert.

Ciao.

Giuseppe

bazcurtis178
Explorer

I think I have cracked it. I think the data coming into index could come in and miss the alert. I have now tweaked the alerts to be cron jobs and I am collecting the data a little more quickly, 15 minutes instead of 20. Thanks for the help.

0 Karma

bazcurtis178
Explorer

I have been checking them minutes after they should trigger. If they should trigger at 20 minutes past the hour I was checking at 25 minutes past.

I have changed them to cron jobs now rather than the GUI x past the hour option. One has already triggered.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...