Alert Manager - Save results to KV store or index?



I'm not sure about the effect of the general setting "Save results to KVStore / index". Is there a difference in the functionality/features of the alert handling depending on this setting?

Can I just activate one or the other? What if I activate both?

Best regards 🙂

Labels (1)
Tags (2)
0 Karma


Hi @HeinzWaescher,

if you save something in an  index, you cannot manually modify it instead you can do this using a KV Store (e.g. using Lookup Editor or scripts).

You can use a summary index e.g. to trace activities on alerts (opening, close, etc...) and a KV store to manage the alerts status.



0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...