Alerting

Alerts not showing up

echalex
Builder

Hi,

I have a search running once an hour, which is configured to raise an alert and email me if events>0. Alert expiration is set to 24 hours. I get the emails, but the alerts do not show up in the "Alerts" link. Also, under "Manager > Searches & reports", the number of alerts stays at 0.

Why is that?

Tags (1)
0 Karma
1 Solution

sowings
Splunk Employee
Splunk Employee

IIRC, the behavior you describe is "tracking", on the configuration page for the search that drives the alert. Tracking is a tick box that keeps track in the Manager UI. Otherwise, you just get the emails.

View solution in original post

0 Karma

sowings
Splunk Employee
Splunk Employee

IIRC, the behavior you describe is "tracking", on the configuration page for the search that drives the alert. Tracking is a tick box that keeps track in the Manager UI. Otherwise, you just get the emails.

0 Karma

echalex
Builder

Yup, that's it! Thanks!

0 Karma

glkadmins
New Member

Can you elaborate on enabling the tracking feature on alerts? I have setup an email alert and I am getting the emails but I cannot see the alert to modify it.

0 Karma

sai33
Explorer

Even i'm facing a similar situation. Any further pointers here!

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...