Alerting

How to Mark ES incident or alert as True/False Positive in Splunk cloud

NDabhi21
Explorer

Hi Team,

Requirement : ES incident/Alerts  should be mark as True Positive or False Positive as verdict .

Please help how I can fulfill this requirement,.

Is there any custom field configuration or any drop down list can be configured ?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...