Alerting

list of all alert in splunk with columns

mailtosnsolutio
Explorer

Hello Splunker,

Hope this message find you well.

Actually i am looking for list of required columns in Alert (basically its activity dashboard)

Basically with all type of alert , I tired to use source="/opt/splunk/var/log/splunk/python.log" sendemail and REST Service Action Alert but it is not giving me following columns as

Need columns as (More Important columns to add to track activity of alerts):
1 ) Alert Name
2.)Alert Sent TO
3.)Alert Sent FROM
4.)Severity
5)SPL run
6)action
7.)host

Labels (1)
0 Karma

anthonymelita
Contributor

Are you trying to get triggered alerts, or just ALL configured/enabled?

You can get some of that info from a REST endpoint.
| rest /services/configs/conf-savedsearches
| search action.email=1 disabled=0
| table action.email.to alert.severity search splunk_server title

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...