I have some alerts configured to email as the only action. Alert.track (Add to Triggered Alerts) is not enabled. I've tried to find evidence anywhere in Splunk logs that these alerts have fired, however, I'm unable.
I've tried looking in :
| rest splunk_server=local /servicesNS/-/-/saved/searches
index=_audit action=alert_fired ss_app=myapp
However, neither appear to show evidence that the alert has fired (Yes, I receive the email). It's possible I'm just missing it or it is logged in another area?
Check scheduler logs. Below query gives list of scheduled searches triggered with alert action.
index=_internal sourcetype=scheduler search_type=scheduled alert_actions!="" | table savedsearch_name, sid, app, alert_actions, scheduled_time, *time
View solution in original post