Alerting

How do I create an email alert based on the following search results?

Yogesh7867
Engager

I want to create an email alert based on my search results. But i am receiving email alert after almost 8 hours. What might be the reason?

I have set the real time alert for this and the time given is rt-2m to rt-0m and throttled it for 4 hrs.

0 Karma

burwell
SplunkTrust
SplunkTrust

I wrote an answer about real-time alerts recently: https://answers.splunk.com/answers/684144/how-to-stop-a-single-account-email-alert-to-trigge.html#an...

Basically I don't recommend using real-time alerts. You can schedule for -2m to now and your indexers won't be as taxed.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...