Alerting

Unable to fetch events for triggered alerts using rest

shreshths
Explorer

Hi,
I'm trying to fetch triggered alerts data using rest command,

|rest timeout=600 splunk_server=local /servicesNS/-/-/alerts/fired_alerts/MyAlert

but i only get a field triggered_alert_count=n,
but i don't get the n events that triggered that alert, how can i get those events ?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...