Splunk Search

How to make a report of details about all savedsearch that fire in a day?

phamxuantung
Communicator

I want to make a report about how many alerts fired in a day. I saw in the job inspection

Capture.PNG

I want all of these info, owner, apps, event, size and runtime. It's to determine how many alert overlapping each other, how many times that alert triggered. Prefer in SPL.

Basically, I want for these information to help me make a detail report about alerts in our system.

Labels (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you could find some solutions from community by searching with Google. Here is one example

index=_internal sourcetype=scheduler search_type=scheduled alert_actions!="" alert_actions!="summary_index"
| table savedsearch_name, sid, app, alert_actions, scheduled_time, *time

Just update table part to get your needed columns and/or add other queries if that one event didn't  contain all needed fields.

r. Ismo 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...