Alerting

Search for Alerts

peter_gianusso
Communicator

How can I do a search for all of the active alerts? I found something that does it via REST but I want to do a search.

Tags (1)
0 Karma
1 Solution

jharty_splunk
Splunk Employee
Splunk Employee

There is another answer on this:
http://splunk-base.splunk.com/answers/517/how-to-search-recent-alerts-fired-by-splunk

index=_audit action=alert_fired | eval ttl=expiration-now() | search ttl>0 | convert ctime(trigger_time) | table trigger_time ss_name severity

View solution in original post

0 Karma

jharty_splunk
Splunk Employee
Splunk Employee

There is another answer on this:
http://splunk-base.splunk.com/answers/517/how-to-search-recent-alerts-fired-by-splunk

index=_audit action=alert_fired | eval ttl=expiration-now() | search ttl>0 | convert ctime(trigger_time) | table trigger_time ss_name severity

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...