<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I retrieve fired alerts in chronological order ? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-retrieve-fired-alerts-in-chronological-order/m-p/693996#M19803</link>
    <description>&lt;P&gt;You could use the /services/search/v2/jobs REST endpoint&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest /services/search/v2/jobs 
| search label = "SOC - *"
| sort - updated
| table label updated author ```add fields as desired```&lt;/LI-CODE&gt;</description>
    <pubDate>Mon, 22 Jul 2024 19:09:22 GMT</pubDate>
    <dc:creator>marnall</dc:creator>
    <dc:date>2024-07-22T19:09:22Z</dc:date>
    <item>
      <title>How can I retrieve fired alerts in chronological order ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-retrieve-fired-alerts-in-chronological-order/m-p/693958#M19802</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I used Splunk REST API with Search endpoint to be able to retrieve the latest fired alerts based on a title search.&lt;/P&gt;&lt;P&gt;I get the fired alerts in alphabetical order but not in chronological order since all the alerts obtained have the default field &amp;lt;updated&amp;gt;1970-01-01T01:00:00+01:00&amp;lt;/updated&amp;gt;.&lt;BR /&gt;&lt;BR /&gt;Here's the url and query I used :&lt;BR /&gt;&lt;A target="_blank" rel="noopener"&gt;https://&amp;lt;host&amp;gt;:&amp;lt;mPort&amp;gt;/services/alerts/fired_alerts?search=name%3DSOC%20-*&amp;amp;&amp;amp;sort_dir=desc&amp;amp;sort_key=updated&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest /services/alerts/fired_alerts/
| search title="SOC - *"
| sort -updated
| table title, updated, triggered_alert_count, author&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31843iE182B0D8DA2E7AF5/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk.PNG" alt="splunk.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Here are the references I used :&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.2/RESTREF/RESTsearch#alerts.2Ffired_alerts" target="_blank" rel="noopener"&gt;Search endpoint descriptions - Splunk Documentation&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.2/RESTREF/RESTprolog#Pagination_and_filtering_parameters" target="_blank" rel="noopener"&gt;Using the REST API reference - Splunk Documentation&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;BR /&gt;So, how can I retrieve fired alerts in chronological order with a title search ? Or how can I obtain a field indicating the date the alert was triggered ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 12:32:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-retrieve-fired-alerts-in-chronological-order/m-p/693958#M19802</guid>
      <dc:creator>av81</dc:creator>
      <dc:date>2024-07-22T12:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: How can I retrieve fired alerts in chronological order ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-retrieve-fired-alerts-in-chronological-order/m-p/693996#M19803</link>
      <description>&lt;P&gt;You could use the /services/search/v2/jobs REST endpoint&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest /services/search/v2/jobs 
| search label = "SOC - *"
| sort - updated
| table label updated author ```add fields as desired```&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 22 Jul 2024 19:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-retrieve-fired-alerts-in-chronological-order/m-p/693996#M19803</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-07-22T19:09:22Z</dc:date>
    </item>
  </channel>
</rss>

