Those are stored into _internal index. If you are not part of splunk admin team, you probably haven't access to it. You could try index=_internal To see if you can see events in that index and if you can then you can try this index="_internal" component=SavedSplunker sourcetype="scheduler" thread_id="AlertNotifier*" NOT (alert_actions="summary_index" OR alert_actions="") app!=splunk_instrumentation
| fields _time app result_count status alert_actions user savedsearch_name splunk_server_group
| stats earliest(_time) as _time count as run_cnt sum(result_count) as result_count values(alert_actions) as alert_actions values(splunk_server_group) as splunk_server_group by app, savedsearch_name user status
| table _time, run_cnt, app, savedsearch_name user status result_count alert_actions splunk_server_group It shows alerts which has previously run and what has happen. If you haven't access to internal logs, then you should ask from your Splunk admin team, that they will check what has happened.
... View more