Splunk provides four built-in alert actions: **Email**, **Webhook**, **Run a Script**, and **Log Event**.
Real-time alerts trigger as soon as events match the condition. Scheduled alerts run at defined intervals (e.g., every 5 minutes) and evaluate the results.
For high-volume environments, scheduled alerts with appropriate cron syntax are far more efficient than real-time alerts.