Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Search and Alert produce different results

$
0
0

When I type this search in the normal Splunk search app, I get normal expected results:

"usb" | transaction host startswith="New USB device found" endswith="USB disconnect" | search NOT keyboard NOT mouse NOT host=xyz

However when I create an alert with the same search pattern, I constantly get results for the host xyz.

I am using the newest Splunk 5.0.3. Is this a bug or is there something happening behind the scenes I don't understand?

The settings for the alert are thus: time range: real time alert mode: once per search condition: always alert action: send email

Any hints?


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>