Is there a possible way to easily correlate alert metadata and search logs?


Hi There,

I've created several alerts with "search & reporting" splunk app. I set the alert action both "alert manager" app and "add to triggered alert" which resulted in logs that contains the alert metadata such as name and creation time.

I would like to join the raw data (search query data) with the alert metadata, however, I couldn't find even a single common field between the 2 log sources.

As a workaround I've added another action to my alert - "log event", and customize an event that contains fields that is shared among both the raw data (search query logs) and the alert metadata logs. This works, but it doesn't feel like the most elegant solution.

I wonder if anyone have encountered similar problem or have an idea how to correlate between "alert manager" metadata logs and search query logs?

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!