Greetings all,
Assuming I have all the appropriate logs ingested and created an alert that triggers when X criteria is met and sends an email to a distlist. Will this alert have a unique ID or tracking # that I can pull up directly in Splunk at a later time to review...or are all the alerts fire-and-forget in Splunk ?
Example, if the alert is triggered and my team gets an email will the alert have something like "Alert# 4857" anywhere in the subject or body and if so will I be able to query Splunk for that alert number at a later time ?