Alerting

"AlertNotifier busy... Consider improving action execution speed or increase action_execution_threads in limits.conf" How to increase the limit?

lukasz92
Communicator

I have very large number (over hundred) of scheduled searches done every minute. Some have alert actions to send an email.

I get thousands of events like this:

WARN SavedSplunker - AlertNotifier busy! Failed to enqueue job for search_id="scheduler_(...)". No actions will be executed. Consider improving action execution speed or increase action_execution_threads in limits.conf

some thousands per day.

I raised this limit to 6 (and to 10 after) - and now I get about 0-100 per day.

How to cope with that? Documentation says, that 10 is the maximum. I want to disable this limit at all.

0 Karma

Masa
Splunk Employee
Splunk Employee

There is no way to make it unlimited. Good practice is to use more search heads with SHC to distribute alerts and increase actions_queue_size (500 or so? ) Any unlimited settings need to be careful. It could use up all available resources.

0 Karma

lukasz92
Communicator

There are 4 searchheads in cluster now.

Thank you for this setting - I will try it.

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...