Dashboards & Visualizations

Alert dashboard

logloganathan
Motivator

Could anyone help to build dashboard for alerts.

how many alert email i got like that?

0 Karma

493669
Super Champion

Hi @logloganathan ,
Below app will help to view fired alerts in dashboards in order to investigate.
https://splunkbase.splunk.com/app/2665/

0 Karma

logloganathan
Motivator

Thanks for the response i need some query help...

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please explain what you mean by "dashboard for alerts".

---
If this reply helps you, Karma would be appreciated.
0 Karma

logloganathan
Motivator

i want to get diaplayed of alert triggered and email sent

0 Karma

Sukisen1981
Champion

hi @logloganathan - You are probably using an email subject with static sentence and some dynamic tokens and the same in the mail body.
Assuming you build a 1 panel dashboard you can just have count as first column, the subject in second column and the body in the 3rd column.
Basically, if you are able to pass tokens to the email subject and body (along with standard static text) , there is no reason why you can not do the same with the same search query in a panel. How you want the look and feel of the panel is up to you.

0 Karma

Sukisen1981
Champion

hi @logloganathan
The easiest way is to have the same search THAT triggers your alert saved as a panel in your dashboard.
For example, index="aaa"|stats count|where count >0 run at an hourly frequency which triggers if count>0. The same search saved as a panel with a bin of 1 hour , for say over the last 24 hrs will give you the number of alerts you received due to this alert in the last 24 hrs.
But are you asking for something else :)?

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...