Alerting

Out of 10-15 users with permission, can we identify who disabled an alert?

Explorer

We had created alert to catch error in logs and gave permission to group(10-15 users) to edit alert but someone disabled alert due to which alert didn't trigger. Just wanted to check if there is any way to find user who had disabled alert?

0 Karma

Champion

Determine when the alert was not executed. Then, check the user who logged in at that time.

It seems that it can be monitored by setting it.

https://answers.splunk.com/answers/448625/how-to-monitor-changes-made-to-the-inputsconf-file.html

0 Karma