list_triggered_alerts
List recent triggered Splunk alerts and their details, including saved search name, trigger time, owner/app, and trigger reason. Supports name and time filters.
Instructions
List fired alerts and their details. Use this to review recent triggered alerts, including saved search name, trigger time, owner/app, and trigger reason. Supports a name filter and a max results cap. Note: Splunk's fired alerts feed may not strictly filter by time; earliest/latest are advisory.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| count | No | Maximum number of alert groups to return (default: 50) | |
| earliest_time | No | Advisory filter for earliest trigger time (default: '-24h@h') | -24h@h |
| latest_time | No | Advisory filter for latest trigger time (default: 'now') | now |
| search | No | Case-insensitive substring filter applied to alert group name |