Splunk Search

How to search to find disabled alert?

kimberlytrayson
Path Finder

Hi!

I'm using Splunk cloud. Trying to create alert to catch event when someone disabling alert.
Need advice on the search for this alert, since has no luck with digging into `index=_* disbled_alert_name`

0 Karma

m_pham
Splunk Employee
Splunk Employee

There isn't a great way to do this due to Splunk not tracking these types of changes. There is a Splunk idea that Splunk is working on that resolves some of the shortcomings of the current audit log.

https://ideas.splunk.com/ideas/E-I-49

 

0 Karma

Brausepaule
Path Finder

how many users are able to edit your alerts?

Maybe you should revisit your permissions on alerts first 😉

0 Karma

Brausepaule
Path Finder

Hi,

all alerts should be saved searches and you can query them like explained here:
https://community.splunk.com/t5/Alerting/How-can-I-query-to-get-all-alerts-which-are-configured/td-p...

as you only want to find disabled alerts (there are already a lot by default) you should only scan for line items where disabled=1

do that in a saved search itself quering all disabled saved searches..and it should work

0 Karma

kimberlytrayson
Path Finder

Hi, @Brausepaule , this is not exactly what I'm looking for, but maybe I can get something out of it.

I'm looking for a way to catch event when someone disabling the alert. Suggested search doesn't return information about who disabled the alert and when.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kimberlytrayson,

with this command you have the list pf all savedsearches, so you can identify the disabled ones:

| rest /servicesNS/-/-/saved/searches splunk_server=local

Ciao.

Giuseppe

0 Karma

kimberlytrayson
Path Finder

Hi, @gcusello  , this is not exactly what I'm looking for, but maybe I can get something out of it.

I'm looking for a way to catch event when someone disabling the alert. Suggested search doesn't return information about who disabled the alert and when.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...