I'm application analyst that monitors splunk alerts. We monitor OOM, CPU usage and other data. We receive alerts via MS outlook.
Is there a way to pull reports on the splunk alerts for the last 6 months. I'd like to see how many alerts we receive daily, monthly, etc. Is that possible via splunk?
Here are the details of Splunk version which I am using: 6.6.1
Hi bjaylsu,
have a look at this answer https://answers.splunk.com/answers/305328/how-to-search-the-names-of-triggered-alerts-their.html#ans... it will provide you a search that creates a report of triggered alerts and their thresholds.
Be aware that you need to have the admin role assigned to be able to access index=_audit
Hope this helps ...
cheers, MuS