Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

alerts related question

$
0
0

Hello there,

is there a way to extract host(not the indexer) information from the generated alerts using search? i have tried below

index=_audit action=alert_fired

which gives me sid and then I used below command to find hosts associated with particular alert

|loadjob <sid>

is there any other way to find out complete alert information using single search which shows host name, alert name, severity, sid, search job etc?

Thx.


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>