We Want to create a report based on the internal index,
Today we have lot of alerts created, and it is becoming a challenge to manage the alerts. This report will tell us what alerts were triggered, when it was triggered, how many times, and to whom it was sent.
Can this be achieved?
Hi athorat,
take a look at this answer https://answers.splunk.com/answers/305328/how-to-search-the-names-of-triggered-alerts-their.html which is kind of similar - just misses the to whom it was sent....but you should be able to get it as well from the first search.
Hope this helps ...
cheers, MuS