We have an odd use case to potentially create a large number of alerts using the alert "tracking" option. We would like to know how/where these "alerts" are stored to plan for disk or other resources.
We would suspect a directory like $SPLUNKHOME/var/run/splunk/dispatch on a search head or an index but would need to know for sure. We have multiple indexers fronted with a search head.
Thoughts? Thanks in advance.