<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the difference between alert and report? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368690#M6504</link>
    <description>&lt;P&gt;This answer is incorrect.  See my answer.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Apr 2020 12:54:55 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2020-04-03T12:54:55Z</dc:date>
    <item>
      <title>What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368683#M6497</link>
      <description>&lt;P&gt;Could anyone please provide a difference between report and alert?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 22:03:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368683#M6497</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2020-06-09T22:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368684#M6498</link>
      <description>&lt;P&gt;A report can be used in a dashboard. It does have to trigger anything.&lt;/P&gt;

&lt;P&gt;You can reference the reports by their name into a dashboard instead of placing them in plain SPL&lt;/P&gt;

&lt;P&gt;An alert is based on a scheduled saved search that whenever certain conditions are overcome, generates one or more actions to be executed.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.2/Alert/AlertWorkflowOverview"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.2/Alert/AlertWorkflowOverview&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 16:07:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368684#M6498</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-03-20T16:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368685#M6499</link>
      <description>&lt;P&gt;The main difference between an alert and a report is the trigger condition.  With the trigger condition an alert will only do an action under the specified circumstances. Where a scheduled report will ALWAYS do it's action if one is selected and an unscheduled report will only run when chosen. &lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 17:08:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368685#M6499</guid>
      <dc:creator>kmaron</dc:creator>
      <dc:date>2018-03-20T17:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368686#M6500</link>
      <description>&lt;P&gt;@logloganathan could you elaborate on your use case or the reason for this question? We would definitely want to assist but without understanding your need we might be shooting in the dark!&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 18:34:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368686#M6500</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-20T18:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368687#M6501</link>
      <description>&lt;P&gt;Because i can use same query in report and alert without triggering any action&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 06:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368687#M6501</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-21T06:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368688#M6502</link>
      <description>&lt;P&gt;But this is not quite true. A report can have actions. I think @kmaron's response is correct - a saved search is an alert if it has a trigger condition.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 18:30:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368688#M6502</guid>
      <dc:creator>ruman_splunk</dc:creator>
      <dc:date>2019-09-09T18:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368689#M6503</link>
      <description>&lt;P&gt;Originally only &lt;CODE&gt;alerts&lt;/CODE&gt; had &lt;CODE&gt;alert actions&lt;/CODE&gt; but customers insisted and now &lt;CODE&gt;reports&lt;/CODE&gt; also can have &lt;CODE&gt;alert actions&lt;/CODE&gt; so literally there is no functional difference between the two.  There is now only a &lt;CODE&gt;taxonomical&lt;/CODE&gt; difference which you are free to slice any way that you like.  Settings-wise, the difference between the two now is defined in &lt;CODE&gt;savedsearches.conf&lt;/CODE&gt; as: &lt;CODE&gt;alert.track=1&lt;/CODE&gt; means &lt;CODE&gt;alert&lt;/CODE&gt; and &lt;CODE&gt;alert.track=0&lt;/CODE&gt; means &lt;CODE&gt;report&lt;/CODE&gt;.  That is it.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 12:54:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368689#M6503</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-04-03T12:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368690#M6504</link>
      <description>&lt;P&gt;This answer is incorrect.  See my answer.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 12:54:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368690#M6504</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-04-03T12:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368691#M6505</link>
      <description>&lt;P&gt;This is incorrect.  See my answer.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 12:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368691#M6505</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-04-03T12:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368692#M6506</link>
      <description>&lt;P&gt;This is incorrect.  See my answer.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 12:55:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368692#M6506</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-04-03T12:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368693#M6507</link>
      <description>&lt;P&gt;This answer is incorrect.&lt;/P&gt;

&lt;P&gt;Here's a savedsearches.conf entry with alert.track=false, note how in the screenshot the corresponding alert action "Add to triggered Alerts" is not selected.&lt;BR /&gt;
Yet the same screenshot show the UI declares this as type Alert.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://i.imgur.com/4mZJylC.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Here's the corresponding btool output:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://i.imgur.com/FF7QClf.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;The two previous answers from 2019 are correct, a report triggers always (savedsearches.conf counttype=always) while an alert has a condition (counttype!=always).&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 16:09:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/368693#M6507</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2020-04-03T16:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/537063#M10163</link>
      <description>&lt;P&gt;After many test, my saved search is still in mode "Report" with only "alert.track=1". An alert type seems to be consisted of 3 points:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A cron schedule&lt;/LI&gt;&lt;LI&gt;A trigger condition&lt;/LI&gt;&lt;LI&gt;A trigger actions&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In my case, here is the options used with the endpoint API "POST /servicesNS/-/-/saved/searches" to get an alert type:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;"is_scheduled": 1,&lt;/LI&gt;&lt;LI&gt;"alert_type": "number of events"&lt;/LI&gt;&lt;LI&gt;"alert_comparator": "greater than",&lt;/LI&gt;&lt;LI&gt;"alert_threshold": 0,&lt;/LI&gt;&lt;LI&gt;"alert.track": 1&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If I remove one of these options, I get a report saved search instead of alert. With the configuration file (savedsearches.conf), the options are "cron_schedule, enableSched, counttype, relation, alert.track".&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 14:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/537063#M10163</guid>
      <dc:creator>nrodrigues</dc:creator>
      <dc:date>2021-01-25T14:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between alert and report?</title>
      <link>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/553198#M10540</link>
      <description>&lt;P&gt;To convert a report to an alert, open the &lt;EM&gt;Advanced Edit,&amp;nbsp;&lt;/EM&gt;and set the filter to&amp;nbsp; &lt;FONT face="courier new,courier"&gt;alert_&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Then set:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;alert_type&lt;/LI&gt;&lt;LI&gt;alert_comparator&lt;/LI&gt;&lt;LI&gt;alert_threshold&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a simple example:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Lowell_0-1622064003880.png" style="width: 812px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14323iE3984A2658FFCE90/image-dimensions/812x403?v=v2" width="812" height="403" role="button" title="Lowell_0-1622064003880.png" alt="Lowell_0-1622064003880.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are searching the rest endpoint and trying to classify your saved searches, here's a search I find helpful to start from:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;| rest splunk_server=local /services/saved/searches&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| fields - display.* dispatch.*&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| search is_visible=1 AND disabled!=true AND is_scheduled=1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| eval type=if(alert_type="always", "report", "alert")&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| table title type disabled scheduled cron_schedule eai:acl.app eai:acl.owner actions search&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 21:26:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/What-is-the-difference-between-alert-and-report/m-p/553198#M10540</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2021-05-26T21:26:06Z</dc:date>
    </item>
  </channel>
</rss>

