Alerting

How do you search log that triggered fired alerts

arrowecssupport
Communicator

Is it possible include the data from the log that a fired alert was triggered off of?

So for example, our web server creates a log where someone from a bad IP address is connecting in, that triggers an email alert to the admin team.

Later down the road, I want to see all fired alerts and generate a report that shows the time the alert was triggered and the IP address value that came from the original web server log.

But to be clear I need this to contain the fired alerts audit log so I know I'm comparing the real log from the web server and the corresponding fired alert

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...