Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Alert deleted by the Splunk system

$
0
0
Hello everyone, I have a problem with an alert removed without a user's action, when I join the Splunk logs: splunk_server = "XXX" index=_audit host=YourHostName action=alert_deleted I do not see deletion events, which may have occurred? some action of the system? How can I identify the cause of the deletion of the alert?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>