Splunk Enterprise Security

How to find the most use cases trigger alerts in Splunk?

engmohdissam
New Member

Greetings!

I need to know how I can find the most use cases trigger alerts in Splunk.

is there any specific search query that can help? I need the use case name and the count of the alerts 

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

See if this query helps.

| rest /servicesNS/-/-/saved/searches splunk_server=local 
```Ignore reports and disabled searches```
| search alert_type!="always" disabled=0 
| where triggered_alert_count > 0 
| table title eai:acl.owner eai:acl.app triggered_alert_count
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...