1. Home
  2. Alert Rules Engine
  3. Alert Rules Engine: Stop Flag

Alert Rules Engine: Stop Flag

At the bottom of any rule setup window, there is an option to stop processing after the rule has been applied.


Every alert sent to Splunk On-Call, runs through the list of rules from top to bottom before reaching the timeline.  (More on managing and ordering rules below)  This check box allows you to stop an alert from continuing to process through subsequent rules.  This has performance advantages (speeds up processing of the alert) and allows you to prevent subsequent rules from overwriting the current rule after it has acted upon the alert.

Updated on November 13, 2020

Was this article helpful?

Related Articles