Alerting

Action log of emails sent as trigger from alert

arrowecssupport
Communicator

Where can i see the list of emails sent as a trigger action from an alert. Is this in the audit log or a log file on the cli?

Tags (1)
0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust

when you create the alert, you can enable "Add to Triggered Alerts" action, so that, you can review all recently triggered alerts on the Triggered Alerts page.
http://docs.splunk.com/Documentation/Splunk/6.4.2/Alert/Triggeredalertaction
http://docs.splunk.com/Documentation/Splunk/6.4.2/Alert/Reviewtriggeredalerts

Details of triggered alerts are available for 24 hours by default.

updated -
this query will give us a list of alerts fired in last 1day -

index=_audit action=alert_fired earliest=-1d@d
thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

inventsekar
SplunkTrust
SplunkTrust

when you create the alert, you can enable "Add to Triggered Alerts" action, so that, you can review all recently triggered alerts on the Triggered Alerts page.
http://docs.splunk.com/Documentation/Splunk/6.4.2/Alert/Triggeredalertaction
http://docs.splunk.com/Documentation/Splunk/6.4.2/Alert/Reviewtriggeredalerts

Details of triggered alerts are available for 24 hours by default.

updated -
this query will give us a list of alerts fired in last 1day -

index=_audit action=alert_fired earliest=-1d@d
thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...