Splunk® Enterprise

Alerting Manual

Download manual as PDF

Download topic as PDF

Monitor triggered alerts

Add an alert to a list of triggered alerts. Review triggered alerts by app context, owner, and severity level.

Add an alert to the Triggered Alerts list

  1. Use one of the following options depending on whether you are creating a new alert or editing an existing alert.
    Option Steps
    Create a new alert From the Search page in the Search and Reporting app, select Save As > Alert. Enter alert details and configure triggering and throttling as needed.
    Edit an existing alert From the Alerts page in the Search and Reporting app, select Edit>Edit actions for an existing alert.
  2. From the Add Actions menu, select Add to triggered alerts.
  3. Select an alert Severity level.
    Severity levels are informational only. They are used to group alerts in the Triggered Alerts list. The default level is Medium.
  4. Click Save.


Reviewing recently triggered alerts

You can see records of recently triggered alerts from the Triggered Alerts page or from an Alert Details page. The Triggered Alerts page shows all instances of triggered alerts. See Review triggered alerts for more information on viewing and interpreting triggered alerts.

Triggered alert details are available for twenty-four hours by default. See Configure triggered alert expiration for information on changing this expiration setting.

PREVIOUS
Log events
  NEXT
Run a script alert action

This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 7.0.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters