Alerting

Do triggered alerts have a unique ID or tracking # (and can they be retreived) ?

fzuazo
Path Finder

Greetings all,

Assuming I have all the appropriate logs ingested and created an alert that triggers when X criteria is met and sends an email to a distlist. Will this alert have a unique ID or tracking # that I can pull up directly in Splunk at a later time to review...or are all the alerts fire-and-forget in Splunk ?

Example, if the alert is triggered and my team gets an email will the alert have something like "Alert# 4857" anywhere in the subject or body and if so will I be able to query Splunk for that alert number at a later time ?

Tags (1)
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...