<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use REST in search to get trigger times of alerts in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Use-REST-in-search-to-get-trigger-times-of-alerts/m-p/532838#M10055</link>
    <description>&lt;P&gt;Looks like this due to user limitations. I tried it on my home search and it seems like it should get what I want.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Dec 2020 15:58:20 GMT</pubDate>
    <dc:creator>aohls</dc:creator>
    <dc:date>2020-12-11T15:58:20Z</dc:date>
    <item>
      <title>Use REST in search to get trigger times of alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Use-REST-in-search-to-get-trigger-times-of-alerts/m-p/532818#M10051</link>
      <description>&lt;P&gt;I am trying to work around not having access to the _internal index; I can't get access at this time. I want to add annotations to a dashboard showing the last time certain alerts triggered. I know how to get an annotation working; I used loadjob but the issue is I can't get historical data accurately it seems. I want to be able to look at the previous day and then see alerts that fired for the time period.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was doing something like the following; I haven't used REST much and am still exploring it:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|rest /servicesNS/-/-/searches
|join title
[| rest /servicesNS/-/-/alerts/fired_alerts]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 15:13:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Use-REST-in-search-to-get-trigger-times-of-alerts/m-p/532818#M10051</guid>
      <dc:creator>aohls</dc:creator>
      <dc:date>2020-12-11T15:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: Use REST in search to get trigger times of alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Use-REST-in-search-to-get-trigger-times-of-alerts/m-p/532825#M10053</link>
      <description>&lt;P&gt;What results did you expect from that query and what results did you get?&lt;/P&gt;&lt;P&gt;Have you tried this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|rest /servicesNS/-/-/searches
|join title
[| rest /servicesNS/-/-/alerts/fired_alerts]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 15:31:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Use-REST-in-search-to-get-trigger-times-of-alerts/m-p/532825#M10053</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-11T15:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Use REST in search to get trigger times of alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Use-REST-in-search-to-get-trigger-times-of-alerts/m-p/532831#M10054</link>
      <description>&lt;P&gt;So when doing this I only get one result, using a specific alert I know has fired a few times in the last 4 hours. What I want is to essentially get the historical trigger times of the alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know _audit is the best way; I will not get granted access to this right now though but trying to work around it since the annotations would be very useful.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 15:37:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Use-REST-in-search-to-get-trigger-times-of-alerts/m-p/532831#M10054</guid>
      <dc:creator>aohls</dc:creator>
      <dc:date>2020-12-11T15:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Use REST in search to get trigger times of alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Use-REST-in-search-to-get-trigger-times-of-alerts/m-p/532838#M10055</link>
      <description>&lt;P&gt;Looks like this due to user limitations. I tried it on my home search and it seems like it should get what I want.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 15:58:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Use-REST-in-search-to-get-trigger-times-of-alerts/m-p/532838#M10055</guid>
      <dc:creator>aohls</dc:creator>
      <dc:date>2020-12-11T15:58:20Z</dc:date>
    </item>
  </channel>
</rss>

