Hello All,
Sorry to ask a silly question, I had a look around, but unable to find a solution.
When we set an alert in Splunk, there is an Expires Parameter.
I understand this is TTL for the Alert (Sorry if I have misunderstood it).
I don't want my Alert to Expire.
How can I achieve this please?
If there is no means to achieve this, is there a way to trigger a notification, when that alert is about to expire please?
I tried couple of options in alert setting, to see if splunk triggers a notification when an alert expires, I am afraid no notification was triggered.
For example set "Trigger Condition", "Trigger Time" and set the alert to Expire in 10 mins. The alert Expired but no notification was triggered via email.
I had a feeling it won't work, as Trigger Condition means - The condition that triggers the alert and NOT alert expiry - but just tried my luck!
Best Regards,
↧