- The List in Triggered Alert action is enabled for the alert.
- The alert triggered recently.
- The retention time span for the alert has not been reached.
- The triggered alert listing has not been deleted.
Open the Alert Manager
The Alert Manager is available from the Splunk Web menu. When listing triggered alerts, the Alert Manager provides details on the following:
- Time: When the alert fired.
- Fired alerts: The name of the alert.
- App: The app for the alert.
- Type: Real-time or scheduled.
- Severity: The severity level.
- Mode: Digest or Per Result. For Digest, the alert represents a set of events. Per Result represents a single event.
- Actions: Links to view results of the alert, edit the base search, and delete the triggered alert listing.
- From the Splunk Enterprise menu bar, select Activity > Triggered Alerts.
The Alert Manager displays the triggered alerts that are available for viewing.
- In the Alert Manager, filter the results according to App, Owner, Severity, and Alert name.
- (Optional) Use the keyword search to find fired alerts by alert name or app name containing the alert.
- (Optional) Take the following actions from the Alert Manager:
- View the results.
- Edit the search for an alert.
- Delete a triggered alert listing.
Enable an alert for listing in the Alert Manager
There are several ways you can enable or disable an action for an alert. To make an alert eligible for listing in the Alert Manager, enable the List in Triggered Alerts action.
The dialog to enable this action appears in various workflows.
- When creating the alert.
- From the listing of alerts in the Alerts page, select Edit > Edit Actions.
- From an alert detail page, for Actions, select Edit.
- From Settings > Searches, reports, and alerts, click the name of the alert. Scroll to the List in Triggered Alerts check box.
When listing an alert, you specify the Severity of the alert. Severity levels are informational only. They let you group and highlight alerts in the Alert Manager according to severity level.
By default, the Alert Manager retains a listing of a triggered alert for 24 hours. You can customize the alert retention period from Settings. After the retention period expires, the alert is no longer available from the Alert Manager.
You can also manually delete the listing of an alert from the Alert Manager.
- From the Splunk Enterprise menu bar, select Settngs > Searches, reports, and alerts.
- In the listing, click the Search Name for the alert you want to modify.
- In the dialog box that opens, scroll to the Expiration menu.
- Select a preset from the menu or select Custom to define a custom time for expiration.
The Expiration setting applies only to alerts that enable the List in Triggered Alerts action.
- Click Save.
Delete a triggered alert listing
You can remove a triggered alert listing from the Alert Manager in the following ways:
- Specify a retention time
The triggered alert listing is deleted when the retention time expires. See Alert retention.
- Delete triggered alert listings manually
You can select one or more alerts from the listing and click Delete. You can delete individual alerts by clicking the Delete link in the listing.
- Disable the alert
Disabling an alert removes all listings of triggered alerts from the Alert Manager. It also removes the listing from the alert details page. You can disable an alert from Settings, the Alerts page, and the detail page for an alert.
Configure alerts in savedsearches.conf
This documentation applies to the following versions of Splunk® Enterprise: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15