I've created an alert for Account Expired.
However, the triggered alert disappears when I do a splunk restart.
Is there any way to prevent this alert from disappearing? Any config setting?
In case you wanted to know the alert information:
- Settings:
- Alert Type = Scheduled
- Runs every day at 23:00
- Expires 24 hours
- Trigger Conditions
- Trigger alert when Number of Results is greater than 0
- Trigger Once
- Trigger Action
- Add to Triggered Alerts with Severity Critical