Hi,
I have same issue as mentioned in this question (https://answers.splunk.com/answers/329954/how-can-i-create-a-report-on-alert-information-wha.html?ut...) and looking for resolution. I followed the same query but it didn't work for me. Can you guys please help me out.
FYI: I am using enterprise splunk, version 6.3.2
I was able to get the list of all the enabled alert from here: | rest /servicesNS/-/-/saved/searches
But I need to get the details of how many times the alert was triggered in particular time duration, what was the alert and what time(when) ?
Thank you!
Hi!
Have you looked at Activity > Triggered alerts? That provides me the view/dashboard I'm needing.
Just sharing.
Cheers!
Hi gabarrygowin,
Nope, that is not helpful. I f I need to see the details of the older alerts which were triggered, this won't help.