<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Triggered Alerts Results in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/536030#M151539</link>
    <description>I don't have a suggestion other than to use the built-in Triggered Alerts dashboard.</description>
    <pubDate>Fri, 15 Jan 2021 15:51:42 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-01-15T15:51:42Z</dc:date>
    <item>
      <title>Triggered Alerts Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/535872#M151477</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm looking to get the triggered alert results with alert name and triggered time in one table. Being very simple&lt;/P&gt;&lt;P&gt;Column 1 triggered alert name&lt;/P&gt;&lt;P&gt;Column 2 triggered time&lt;/P&gt;&lt;P&gt;Column 3 Results of the triggered alert&lt;/P&gt;&lt;P&gt;Could anyone help me with this&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 16:28:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/535872#M151477</guid>
      <dc:creator>abhi22</dc:creator>
      <dc:date>2021-01-14T16:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Triggered Alerts Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/535920#M151490</link>
      <description>&lt;P&gt;We need more information.&amp;nbsp; Based on what's in the question, the best we can offer is&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;some search&amp;gt; 
| table AlertName _time AlertResults&lt;/LI-CODE&gt;&lt;P&gt;Tell us more about the data and we may be able to add some details.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 21:44:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/535920#M151490</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-14T21:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: Triggered Alerts Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/535938#M151500</link>
      <description>&lt;P&gt;Hello Richgalloway,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am trying to get the Trigger Alerts dashboard which will show the Alerts which are triggered, I am able to achieve the same using below search query:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;index=_audit action=alert_fired ss_app=* | eval ttl=expiration-now() | search ttl&amp;gt;0 | convert ctime(trigger_time) | table trigger_time ss_name severity | rename trigger_time as "Alert Time" ss_name as "Alert Name" severity as "Severity" , Apart from this in another column I also need the results of the triggered alert (events which caused the alert to trigger) or the link which directs to the results of that particular alert . Could you please suggest me on this&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 14:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/535938#M151500</guid>
      <dc:creator>abhi22</dc:creator>
      <dc:date>2021-01-15T14:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Triggered Alerts Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/536025#M151535</link>
      <description>&lt;P&gt;Alert results are not available via SPL because they are not indexed nor does any REST command expose them.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 15:31:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/536025#M151535</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-15T15:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Triggered Alerts Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/536028#M151537</link>
      <description>&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;At least when we click on the alert in the dashboard, it should redirect to the results/events which triggered the alert, please suggest if the above is possible and how we can achieve the same&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 15:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/536028#M151537</guid>
      <dc:creator>abhi22</dc:creator>
      <dc:date>2021-01-15T15:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Triggered Alerts Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/536030#M151539</link>
      <description>I don't have a suggestion other than to use the built-in Triggered Alerts dashboard.</description>
      <pubDate>Fri, 15 Jan 2021 15:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Triggered-Alerts-Results/m-p/536030#M151539</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-15T15:51:42Z</dc:date>
    </item>
  </channel>
</rss>

