Dashboards & Visualizations

I am trying to build a Splunk dashbaord with all the alerts - with details such as last trigger time, alert creation date.- Any help?

amalkapuram
New Member

I tried using |rest command but was unsuccessful in finding last trigger time, alert creation date fields in that. Please help.

Tags (1)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

This search should have most of the details you want.

| rest /services/saved/searches

You'll have to join it to the _audit index to find out when they were created though

View solution in original post

0 Karma

mattymo
Splunk Employee
Splunk Employee

Check monitoring triggered alerts http://docs.splunk.com/Documentation/Splunk/6.6.2/Alert/Triggeredalertaction

http://docs.splunk.com/Documentation/Splunk/6.6.2/Alert/Reviewtriggeredalerts

Splunk's built in views should provide some guidance or may achieve what u need.

Also alert manager likely has some nice views once you get deeper into alerting and workflow

https://splunkbase.splunk.com/app/2665/

- MattyMo
0 Karma

jkat54
SplunkTrust
SplunkTrust

This search should have most of the details you want.

| rest /services/saved/searches

You'll have to join it to the _audit index to find out when they were created though

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...