I want to search the "Alert" information, which is the new feature of splunk 4.2 , and display alerts in the dashboard by my way.
Could I do this by search command? and where is the alert information stored?
Leo Wang
Alerts are stored at:
| rest /services/alerts/fired_alerts splunk_server=local
As far as searching and reporting on alerts - I wish I knew!! I am looking for the same information, I want to create a summary dashboard for my alerts. I'll post here if I find any answers 😞