Please I am looking for a query to search for the top alerts that fired within 2 weeks (or within a time frame).
I am also looking for a query to show anomalies within a time frame
Start with this query.
| rest/servicesNS/-/-/alerts/fired_alerts| search NOT title="-"
Your second question is far too broad to attempt to answer. Please post a new question with more specifics. What kind of data? What is considered an anomaly? What time frame?