Splunk Search

How to search to find disabled alert?

kimberlytrayson
Path Finder

Hi!

I'm using Splunk cloud. Trying to create alert to catch event when someone disabling alert.
Need advice on the search for this alert, since has no luck with digging into `index=_* disbled_alert_name`

0 Karma

m_pham
Splunk Employee
Splunk Employee

There isn't a great way to do this due to Splunk not tracking these types of changes. There is a Splunk idea that Splunk is working on that resolves some of the shortcomings of the current audit log.

https://ideas.splunk.com/ideas/E-I-49

 

0 Karma

Brausepaule
Path Finder

how many users are able to edit your alerts?

Maybe you should revisit your permissions on alerts first 😉

0 Karma

Brausepaule
Path Finder

Hi,

all alerts should be saved searches and you can query them like explained here:
https://community.splunk.com/t5/Alerting/How-can-I-query-to-get-all-alerts-which-are-configured/td-p...

as you only want to find disabled alerts (there are already a lot by default) you should only scan for line items where disabled=1

do that in a saved search itself quering all disabled saved searches..and it should work

0 Karma

kimberlytrayson
Path Finder

Hi, @Brausepaule , this is not exactly what I'm looking for, but maybe I can get something out of it.

I'm looking for a way to catch event when someone disabling the alert. Suggested search doesn't return information about who disabled the alert and when.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kimberlytrayson,

with this command you have the list pf all savedsearches, so you can identify the disabled ones:

| rest /servicesNS/-/-/saved/searches splunk_server=local

Ciao.

Giuseppe

0 Karma

kimberlytrayson
Path Finder

Hi, @gcusello  , this is not exactly what I'm looking for, but maybe I can get something out of it.

I'm looking for a way to catch event when someone disabling the alert. Suggested search doesn't return information about who disabled the alert and when.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...