Splunk Search

How to search to find disabled alert?

kimberlytrayson
Path Finder

Hi!

I'm using Splunk cloud. Trying to create alert to catch event when someone disabling alert.
Need advice on the search for this alert, since has no luck with digging into `index=_* disbled_alert_name`

0 Karma

m_pham
Splunk Employee
Splunk Employee

There isn't a great way to do this due to Splunk not tracking these types of changes. There is a Splunk idea that Splunk is working on that resolves some of the shortcomings of the current audit log.

https://ideas.splunk.com/ideas/E-I-49

 

0 Karma

Brausepaule
Path Finder

how many users are able to edit your alerts?

Maybe you should revisit your permissions on alerts first 😉

0 Karma

Brausepaule
Path Finder

Hi,

all alerts should be saved searches and you can query them like explained here:
https://community.splunk.com/t5/Alerting/How-can-I-query-to-get-all-alerts-which-are-configured/td-p...

as you only want to find disabled alerts (there are already a lot by default) you should only scan for line items where disabled=1

do that in a saved search itself quering all disabled saved searches..and it should work

0 Karma

kimberlytrayson
Path Finder

Hi, @Brausepaule , this is not exactly what I'm looking for, but maybe I can get something out of it.

I'm looking for a way to catch event when someone disabling the alert. Suggested search doesn't return information about who disabled the alert and when.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kimberlytrayson,

with this command you have the list pf all savedsearches, so you can identify the disabled ones:

| rest /servicesNS/-/-/saved/searches splunk_server=local

Ciao.

Giuseppe

0 Karma

kimberlytrayson
Path Finder

Hi, @gcusello  , this is not exactly what I'm looking for, but maybe I can get something out of it.

I'm looking for a way to catch event when someone disabling the alert. Suggested search doesn't return information about who disabled the alert and when.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...