Alerting

Alerts not triggering, but the same search has results

bazcurtis178
Explorer

Hi,

I have 6 Alerts that run on a schedule. Only one of them is working. If I run the search results come back that match. Why would they not be triggering?

 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @bazcurtis178,

did you tested the searches without results in the same time period or after when you checked it?

Please try to run it in the same time period of the schedules alert.

Ciao.

Giuseppe

bazcurtis178
Explorer

I think I have cracked it. I think the data coming into index could come in and miss the alert. I have now tweaked the alerts to be cron jobs and I am collecting the data a little more quickly, 15 minutes instead of 20. Thanks for the help.

0 Karma

bazcurtis178
Explorer

I have been checking them minutes after they should trigger. If they should trigger at 20 minutes past the hour I was checking at 25 minutes past.

I have changed them to cron jobs now rather than the GUI x past the hour option. One has already triggered.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...