Hello Splunker,
Hope this message find you well.
Actually i am looking for list of required columns in Alert (basically its activity dashboard)
Basically with all type of alert , I tired to use source="/opt/splunk/var/log/splunk/python.log" sendemail and REST Service Action Alert but it is not giving me following columns as
Need columns as (More Important columns to add to track activity of alerts):
1 ) Alert Name
2.)Alert Sent TO
3.)Alert Sent FROM
4.)Severity
5)SPL run
6)action
7.)host
Are you trying to get triggered alerts, or just ALL configured/enabled?
You can get some of that info from a REST endpoint.
| rest /services/configs/conf-savedsearches
| search action.email=1 disabled=0
| table action.email.to alert.severity search splunk_server title