Is it possible (or solution) to send email alert from splunk immediately when event occurs?
I would like to be informed "on event", not 1 munute later (1 minute is the minimal time range in search scheduler).
This is a feature that will be included in the upcoming Splunk 4.2 release.
Nice. Thanks for the correction
No this is already available in 4.2
Create your search, select a real-time range (eg 1 minute window) then click 'create an alert'.
I thought this will be in 4.3?
How that 4.2 is released, can you hint as to where to look? I'm only seeing periodic alerts bases on polling.