Dashboards & Visualizations

I am trying to build a Splunk dashbaord with all the alerts - with details such as last trigger time, alert creation date.- Any help?

amalkapuram
New Member

I tried using |rest command but was unsuccessful in finding last trigger time, alert creation date fields in that. Please help.

Tags (1)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

This search should have most of the details you want.

| rest /services/saved/searches

You'll have to join it to the _audit index to find out when they were created though

View solution in original post

0 Karma

mattymo
Splunk Employee
Splunk Employee

Check monitoring triggered alerts http://docs.splunk.com/Documentation/Splunk/6.6.2/Alert/Triggeredalertaction

http://docs.splunk.com/Documentation/Splunk/6.6.2/Alert/Reviewtriggeredalerts

Splunk's built in views should provide some guidance or may achieve what u need.

Also alert manager likely has some nice views once you get deeper into alerting and workflow

https://splunkbase.splunk.com/app/2665/

- MattyMo
0 Karma

jkat54
SplunkTrust
SplunkTrust

This search should have most of the details you want.

| rest /services/saved/searches

You'll have to join it to the _audit index to find out when they were created though

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...