Closed alert status with time when it was triggered first time


Hi everyone

I need a query to check the alert status close with time and when the same alert got triggered 1 st time in Splunk  it may be 1 week before and now we r closing same alert can be triggered multiple time so need an historical data of the alert with current status closed time




Thanks in advance

Labels (1)
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!