Alerting

Alert Manager - Save results to KV store or index?

HeinzWaescher
Motivator

Hi,

I'm not sure about the effect of the general setting "Save results to KVStore / index". Is there a difference in the functionality/features of the alert handling depending on this setting?

Can I just activate one or the other? What if I activate both?

Best regards 🙂

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @HeinzWaescher,

if you save something in an  index, you cannot manually modify it instead you can do this using a KV Store (e.g. using Lookup Editor or scripts).

You can use a summary index e.g. to trace activities on alerts (opening, close, etc...) and a KV store to manage the alerts status.

Ciao.

Giuseppe

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!