Alerting

Alerts not showing up

echalex
Builder

Hi,

I have a search running once an hour, which is configured to raise an alert and email me if events>0. Alert expiration is set to 24 hours. I get the emails, but the alerts do not show up in the "Alerts" link. Also, under "Manager > Searches & reports", the number of alerts stays at 0.

Why is that?

Tags (1)
0 Karma
1 Solution

sowings
Splunk Employee
Splunk Employee

IIRC, the behavior you describe is "tracking", on the configuration page for the search that drives the alert. Tracking is a tick box that keeps track in the Manager UI. Otherwise, you just get the emails.

View solution in original post

0 Karma

sowings
Splunk Employee
Splunk Employee

IIRC, the behavior you describe is "tracking", on the configuration page for the search that drives the alert. Tracking is a tick box that keeps track in the Manager UI. Otherwise, you just get the emails.

0 Karma

echalex
Builder

Yup, that's it! Thanks!

0 Karma

glkadmins
New Member

Can you elaborate on enabling the tracking feature on alerts? I have setup an email alert and I am getting the emails but I cannot see the alert to modify it.

0 Karma

sai33
Explorer

Even i'm facing a similar situation. Any further pointers here!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...