list_triggered_alerts
Retrieve triggered alerts with details such as saved search name, trigger time, and reason. Filter by alert name and limit the number of results.
Instructions
List fired alerts and their details. Use this to review recent triggered alerts, including saved search name, trigger time, owner/app, and trigger reason. Supports a name filter and a max results cap. Note: Splunk's fired alerts feed may not strictly filter by time; earliest/latest are advisory.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| count | No | Maximum number of alert groups to return (default: 50) | |
| earliest_time | No | Advisory filter for earliest trigger time (default: '-24h@h') | -24h@h |
| latest_time | No | Advisory filter for latest trigger time (default: 'now') | now |
| search | No | Case-insensitive substring filter applied to alert group name |