Alerting

Do triggered alerts have a unique ID or tracking # (and can they be retreived) ?

fzuazo
Path Finder

Greetings all,

Assuming I have all the appropriate logs ingested and created an alert that triggers when X criteria is met and sends an email to a distlist. Will this alert have a unique ID or tracking # that I can pull up directly in Splunk at a later time to review...or are all the alerts fire-and-forget in Splunk ?

Example, if the alert is triggered and my team gets an email will the alert have something like "Alert# 4857" anywhere in the subject or body and if so will I be able to query Splunk for that alert number at a later time ?

Tags (1)
Get Updates on the Splunk Community!

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...