Splunk Search

After saving a search as an alert and choose "add to triggered alerts", why do I not see anything in triggered alerts?

CREVITCH
Path Finder

I have been trying to save a search as an alert and make sure I "add to triggered alerts". It appears under settings>searches, reports and alerts. When I click on "view recent" on the searches, reports and alerts page, I see the event. However, I do not see it in triggered alerts. What am I doing wrong?

Thanks

Tags (2)
0 Karma
1 Solution

CREVITCH
Path Finder

I found the reason. Had to do with per search or per event option.

View solution in original post

0 Karma

CREVITCH
Path Finder

I found the reason. Had to do with per search or per event option.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...