Alerting

Do triggered alerts have a unique ID or tracking # (and can they be retreived) ?

fzuazo
Path Finder

Greetings all,

Assuming I have all the appropriate logs ingested and created an alert that triggers when X criteria is met and sends an email to a distlist. Will this alert have a unique ID or tracking # that I can pull up directly in Splunk at a later time to review...or are all the alerts fire-and-forget in Splunk ?

Example, if the alert is triggered and my team gets an email will the alert have something like "Alert# 4857" anywhere in the subject or body and if so will I be able to query Splunk for that alert number at a later time ?

Tags (1)
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!