Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk 6.5.0: When viewing an alert, why does custom time change to the current time and shows no results?

$
0
0
We recently upgraded to 6.5.0. I have several alerts set up to run on a chron schedule and to alert when >= 15 errors. I get the alert. When I view the results in Splunk, it gives me the result as expected (a database number affected and the error count), however when I click on the database to view the error, it changes the time from the custom time (-2m@m through -1m@m) to the current time (the time I clicked on the link) and often shows me no results. This worked fine prior to 6.5.0. Is there a new setting that I need to change or is this a bug?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>