Alerting

sendalert logs not visible in _internal index

krever
Engager

Im executing my custom alert action with sendalert action_name command and it executes correctly.
I can see the output in job logs but it doesnt get indexed in _internal index as standard alerts does.
Can I make somehting to make it work?

0 Karma

harsmarvania57
Ultra Champion
0 Karma

krever
Engager

Yes, my observation is the same. Although I hope for some solution still.

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...