Alerting

Data retention on triggered alerts and sent e-mails

SocMin
New Member

I've been asked to find a solution that will allow me to retain the full details of triggered alerts and the e-mail alerts sent by them.

So far I cannot see any clear way to do this bar perhaps outputting the requested details to a lookup and just copying to a retention mailbox appears to also not be an option.

Has anyone had to meet this kind of retention policy before?

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Could you explain the use case in more detail, please?  How long is the retention period?  Where does the data need to be retained?  What exactly needs to be retained?  Why is a retention mailbox not an option?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...