Find the historical execution of alerts and sending email status


Hi everyone,

I am searching a way to have a list of every alert (sending email) goes along with: schedule (cron), last run,  send email (sent or not)

Until now I can find this list of info but still not success to have the last run and send email



| fields title disabled actions alert.severity cron_schedule is_schedule max_concurrent next_schedule_time run_n_times
| where disabled=0 
|where actions="email"
|table title cron_schedule is_schedule max_concurrent next_schedule_time run_n_times



Anyone has an idea, please? 

Thanks in advanced!

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...