Dashboards & Visualizations

I am trying to build a Splunk dashbaord with all the alerts - with details such as last trigger time, alert creation date.- Any help?

amalkapuram
New Member

I tried using |rest command but was unsuccessful in finding last trigger time, alert creation date fields in that. Please help.

Tags (1)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

This search should have most of the details you want.

| rest /services/saved/searches

You'll have to join it to the _audit index to find out when they were created though

View solution in original post

0 Karma

mattymo
Splunk Employee
Splunk Employee

Check monitoring triggered alerts http://docs.splunk.com/Documentation/Splunk/6.6.2/Alert/Triggeredalertaction

http://docs.splunk.com/Documentation/Splunk/6.6.2/Alert/Reviewtriggeredalerts

Splunk's built in views should provide some guidance or may achieve what u need.

Also alert manager likely has some nice views once you get deeper into alerting and workflow

https://splunkbase.splunk.com/app/2665/

- MattyMo
0 Karma

jkat54
SplunkTrust
SplunkTrust

This search should have most of the details you want.

| rest /services/saved/searches

You'll have to join it to the _audit index to find out when they were created though

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...