Hi All,
I've configured two alerts from the search app in Splunk and did 'save as' from the search bar. These do appear the 'alerts' tab within Alert Manager, but nothing shows up 'incident posture'.
In permission settings for the alert, I've set it to read/write for all Apps, trigger in real-time and a trigger action to call alert manager.
Nothing shows up in 'recent incidents' or in the color coded incident counters in 'incident posture'.
In settings > Incident settings:
" _Key " column is populated, alert column is populated with a name, however 'category, subcategory, tags' are unknown/untagged.
What am I missing please?
Thanks
... View more