How can I do a search for all of the active alerts? I found something that does it via REST but I want to do a search.
There is another answer on this:
http://splunk-base.splunk.com/answers/517/how-to-search-recent-alerts-fired-by-splunk
index=_audit action=alert_fired | eval ttl=expiration-now() | search ttl>0 | convert ctime(trigger_time) | table trigger_time ss_name severity
There is another answer on this:
http://splunk-base.splunk.com/answers/517/how-to-search-recent-alerts-fired-by-splunk
index=_audit action=alert_fired | eval ttl=expiration-now() | search ttl>0 | convert ctime(trigger_time) | table trigger_time ss_name severity