Hi-
I am setting up search pooling on splunk 5.0.7 and testing alerts.
I have two search heads in the pool behind a load balancer.
When i set up the alert on one of the heads, it runs on both (which is the expected behavior), but I receive two copies of the same alert one from each search head in my mailbox.
Since i have configured the alert_actions to use my load balancer hostname instead of the search heads, if i click on the link in the email and get redirected to the search head that did not trigger the alerts, I get "The search you requested could not be found" message.
Is there something I should do to avoid duplicate alerts sent?
Thanks!
N~
PS. I have seen a couple of this same question posted to splunk answers in the past, with no answer.
... View more