Alerting

How to get Alert details to show in dashboard?

avni26
Explorer

Hi ,
I want to show dashboard showing Alert statistics.
Like total number alerts exists on app , Number of alerts sent , Number of alerts triggered , Number of total alerts notified to slack channel etc.
So, how to get all alert details from internal index?
Please suggest.

0 Karma

to4kawa
Ultra Champion
|rest /servicesNS/-/-/saved/searches

OR

index=_internal sourcetype="scheduler"

rest has too much information.
_internal is better.

0 Karma

avni26
Explorer

@to4kawa Is this possible with internal log.. index=_internal ?

0 Karma

avni26
Explorer

Please suggest

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...