Dashboards & Visualizations

Alert dashboard

logloganathan
Motivator

Could anyone help to build dashboard for alerts.

how many alert email i got like that?

0 Karma

493669
Super Champion

Hi @logloganathan ,
Below app will help to view fired alerts in dashboards in order to investigate.
https://splunkbase.splunk.com/app/2665/

0 Karma

logloganathan
Motivator

Thanks for the response i need some query help...

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please explain what you mean by "dashboard for alerts".

---
If this reply helps you, Karma would be appreciated.
0 Karma

logloganathan
Motivator

i want to get diaplayed of alert triggered and email sent

0 Karma

Sukisen1981
Champion

hi @logloganathan - You are probably using an email subject with static sentence and some dynamic tokens and the same in the mail body.
Assuming you build a 1 panel dashboard you can just have count as first column, the subject in second column and the body in the 3rd column.
Basically, if you are able to pass tokens to the email subject and body (along with standard static text) , there is no reason why you can not do the same with the same search query in a panel. How you want the look and feel of the panel is up to you.

0 Karma

Sukisen1981
Champion

hi @logloganathan
The easiest way is to have the same search THAT triggers your alert saved as a panel in your dashboard.
For example, index="aaa"|stats count|where count >0 run at an hourly frequency which triggers if count>0. The same search saved as a panel with a bin of 1 hour , for say over the last 24 hrs will give you the number of alerts you received due to this alert in the last 24 hrs.
But are you asking for something else :)?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...