Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

"ttl" in alert_actions.conf is ignored.

$
0
0
I configured like below in `etc/system/local/alert_actions.conf`. [email] ttl = 1209600 I thought job of scheduled alert that action is sending email, would be expired after 14 days. But my scheduled alert ignored this limit, and it displayed that the alert would be expired after 18 days in search activity. Did I make mistake? If someone tell me some information about it, I appreciate. Additional Information: Splunk ver : 6.6.6 Alert schedule : 0 8 * * 1 earliest : -6d@w1 latest : @w1 I didn't configure any ttl settings in savedsearches.conf

Viewing all articles
Browse latest Browse all 47296