Why was an alert deleted by the Splunk system?

New Member

Hello everyone,

I have a problem with an alert removed without a user's action.

When I join the Splunk logs...

splunk_server = "XXX" index=_audit  host=YourHostName action=alert_deleted

...I do not see deletion events which may have occurred? Is this some action of the system? How can I identify the cause of the deletion of the alert?

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...