Alerting

Use REST for alert information

aohls
Contributor

I am using the rest services within the search to get information on alerts that have triggered. I am trying to piece together alert information and can find most of it. What I am unable to find; maybe not knowing all the fields, is the trigger time. I see that fired_alerts has the next_scheduled_time but I don't see that it has the triggered time. I do not have access to _index so I am working on getting some of this information here if possible.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The unintuitive place to find that is in the triggered_alert_count field in | rest /services/saved/searches

---
If this reply helps you, Karma would be appreciated.
0 Karma

aohls
Contributor

This tells the count for the alert but not the time.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Sorry for providing the wrong information.

The trigger_time field is not returned as part of the general alerts/fired-alerts query.  You get it only when you request information about a specific alert name.

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...