Alerting

Where the Alert results are stored in Splunk ?

sandyIscream
Communicator

I want to get the results of every triggered alert. For example a particular alert is affecting which hosts in my system and what is the respective message that I am getting for each triggered alert.

Thanks in advance.

0 Karma

woodcock
Esteemed Legend

Start with this search:

|rest/servicesNS/-/-/alerts/fired_alerts
0 Karma

cmerriman
Super Champion

I believe they are stored in the same place as saved searches.
$SPLUNK_HOME/var/run/splunk/dispatch/search/ folder

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...