Alert Manager

noun

A feature that enables you to see and manage records of triggered alerts. You access the Alert Manager by clicking the Alerts link at the upper right hand corner of the Splunk Web interface.

The Alert Manager only displays records for alerts that have Tracking selected in their alert definition. It includes a Severity column that enables you to quickly spot alerts that are high priority (this setting is also defined in the alert definition.

You can also click View results for a particular alert record to see the results for the search job artifact associated with it. This can be helpful if you want more information about the specific events that triggered the alert.

Alert records expire after a given amount of time; this is controlled by the Alert expiration setting in the alert definition. For example, you can have all records of a particular alert expire one day after they have been triggered.

For more information

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time