Alerting

Do triggered alerts have a unique ID or tracking # (and can they be retreived) ?

fzuazo
Path Finder

Greetings all,

Assuming I have all the appropriate logs ingested and created an alert that triggers when X criteria is met and sends an email to a distlist. Will this alert have a unique ID or tracking # that I can pull up directly in Splunk at a later time to review...or are all the alerts fire-and-forget in Splunk ?

Example, if the alert is triggered and my team gets an email will the alert have something like "Alert# 4857" anywhere in the subject or body and if so will I be able to query Splunk for that alert number at a later time ?

Tags (1)
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...