Splunk Search

How do you search by specific alert type?

wzgoda
Explorer

Hey,

I was looking run a historical search for a specific alert over a period of time. What search can I run in order to search by alert type?

0 Karma
1 Solution

Raghav2384
Motivator

This should have all the information you want:

index=_internal host=* source=*scheduler.log

Best bet, s.o.s (Splunk On Splunk Application)

Built in: From you splunk web, upper right hand corner, click on - Activity > System Activity > Scheduler > Scheduler Activity by Saved search. This should give you any & all the information you need.

Also, hit the following endpoints:

|rest /services/alerts/alert_actions
|rest /services/alerts/fired_alerts
|rest /services/saved/searches

Hope this helps!

Thanks,
Raghav

View solution in original post

Raghav2384
Motivator

This should have all the information you want:

index=_internal host=* source=*scheduler.log

Best bet, s.o.s (Splunk On Splunk Application)

Built in: From you splunk web, upper right hand corner, click on - Activity > System Activity > Scheduler > Scheduler Activity by Saved search. This should give you any & all the information you need.

Also, hit the following endpoints:

|rest /services/alerts/alert_actions
|rest /services/alerts/fired_alerts
|rest /services/saved/searches

Hope this helps!

Thanks,
Raghav

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...