- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Saved Searches - Log Events to Existing Index - Not working
Hello,
I've created real-time alerts in Splunk Enterprise 7.1.2, and I want to log each triggered event to an index, so I can create a dashboard that shows alerts over time. The task seems pretty straight forward ( create alert, add action, log event, etc); however, I cannot get this to work. I'm trying to redirect this to my existing index.
This seems to be not working, and I don't have access to the main index as per my company's policy. Please help me in logging this event to my custom index.
Looking forward to hear from you.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Are you looking to index events which are triggered through alert?
Then :
2) Create a new index
1) Edit the alert you want to index.Go to Trigger Actions
and click on + Add Actions
2) click on "Log Event" and specify the index details.
Then you should see triggered events in that index
let me know if this helps!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Thanks for the reply.
So you mean to say it won't work with any of the existing indexes? i tried with my existing index and i am not able to query the events after doing the above mentioned steps.
Let me know how can i achieve the same using existing indexes and source types.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Are you looking for a list of alerts that have triggered recently or something more than that?
For triggered alerts, try | rest/servicesNS/-/-/alerts/fired_alerts| search NOT title="-"
. This is maintained automatically by Splunk so you don't have to use your own indexing.
If this reply helps you, Karma would be appreciated.
