Alerting

Where the Alert results are stored in Splunk ?

sandyIscream
Communicator

I want to get the results of every triggered alert. For example a particular alert is affecting which hosts in my system and what is the respective message that I am getting for each triggered alert.

Thanks in advance.

0 Karma

woodcock
Esteemed Legend

Start with this search:

|rest/servicesNS/-/-/alerts/fired_alerts
0 Karma

cmerriman
Super Champion

I believe they are stored in the same place as saved searches.
$SPLUNK_HOME/var/run/splunk/dispatch/search/ folder

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...