
Create real-time alerts
Use a real-time alert to monitor events or event patterns as they happen. You can create real-time alerts with per-result triggering or rolling time window triggering. Real-time alerts can be costly in terms of computing resources, so consider using a scheduled alert when possible.
To compare scheduled and real-time alerts, see Alert types. To review scenarios for alert types and triggering, see Alert type and triggering scenarios.
Create a real-time alert with per-result triggering
Real-time alerts with per-result triggering are sometimes known as "per-result alerts". This alert type and triggering use a continuous real-time search to look for events. Each search result triggers the alert.
- Caution: If you have a Splunk Enterprise high-availability deployment, use per-result triggering with caution. If a peer is not available, a real-time search does not warn that the search might be incomplete. To avoid this issue, use a scheduled alert
Follow these steps to create a real-time alert with per-result triggering.
- Navigate to the Search page in the Search and Reporting app.
- Create a search.
- Select Save As>Alert.
- Enter a title and optional description.
- Specify permissions.
- Select the Real-time alert type.
- Select the Per-Result trigger option.
- (Optional) Configure a trigger throttling period.
- Select one or more alert actions that should happen when the alert triggers.
- Click Save.
Create a real-time alert with rolling window triggering
Real-time alerts with rolling time window triggering are sometimes known as "rolling window alerts". The rolling time window is an interval or increment, such as five minutes. It is not a scheduled time. Because real-time alerts search continuously, the time window applied to events also rolls forward in time.
Use this alert type and triggering when a specific time interval is part of the event pattern you are monitoring in real time. This alert type and triggering are the most resource-demanding alerting option. It can be helpful to consider using another alert type if possible.
Follow these steps to create a real-time alert with rolling window triggering.
- Navigate to the Search page in the Search and Reporting app.
- Create a search.
- Select Save As>Alert.
- Enter a title and an optional description.
- Specify permissions.
- Select the Real-time alert type.
- Select one of the available result-based conditions or enter a custom triggering condition. Do not select per-result triggering.
- Specify a time interval to add to the triggering condition.
- (Optional) Configure a trigger throttling period.
- Select one or more alert actions that should happen when the alert triggers.
- Click Save.
Additional resources
- Learn about alert and alert action permissions in Alert permissions.
- Step through alert examples in Alert examples.
- Learn more about using trigger conditions in Configure alert trigger conditions.
PREVIOUS Alert scheduling tips |
NEXT Configure alert trigger conditions |
This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3
Feedback submitted, thanks!