Alerts are the actions that a saved search result does when a specific amount of time has passed. Following an alert, activities such as sending an email or sending a message will be initiated. In Splunk, there are two types of alters:
- Real-time alerts: we can divide the real-time alerts into two parts, pre-result, and rolling-window alerts. The pre-result alert gets triggered with every search, while rolling-window alerts are triggered when a specific criterion is met by the search.
- Scheduled Alerts: As the name suggests, scheduled alerts can be initialized to trigger multiple alerts based on the set criteria.