FiredAlertDetails
List the unexpired triggered instances of fired alerts in Splunk. By default all fired alerts are returned; filter on SavedSearchName to return the instances of a single alert.
Columns
| Name | Type | Description |
| Name [KEY] | String | The unique identifier of the fired alert instance. |
| Id | String | The REST resource link for the fired alert instance. |
| SavedSearchName | String | The name of the saved search that triggered the alert. Filtering on this column scopes the results to a single alert. |
| UpdatedAt | Datetime | Datetime of the last update of the fired alert instance. |
| Published | Datetime | Datetime when the fired alert instance was published. |
| Author | String | The Splunk user that owns the fired alert instance. |
| App | String | The Splunk app context where the fired alert is shared. |
| CanList | Boolean | Indicates whether the entry can be listed by the user. |
| CanWrite | Boolean | Indicates whether the entry can be modified by the user. |
| Modifiable | Boolean | Indicates whether the entry can be modified. |
| Owner | String | The Splunk user that owns the entry. |
| ReadPermissions | String | Permissions to read this entry. |
| WritePermissions | String | Permissions to write to this entry. |
| Removable | Boolean | Indicates whether the entry can be removed. |
| Sharing | String | The entry sharing type. |
| Actions | String | Any additional alert actions triggered by this alert. |
| AlertType | String | Indicates whether the alert was historical or real-time. |
| DigestMode | Boolean | Indicates whether the alert actions are applied to the entire result set or to each individual result. |
| ExpirationTimeRendered | String | The human-readable expiration time of the fired alert instance. |
| Severity | Integer | The severity level of the alert. Ranges from Info, Low, Medium, High, to Critical. Default is Medium. |
| Sid | String | The search ID of the search that triggered the alert. |
| TriggerTime | Long | The epoch time, in seconds, when the alert was triggered. |
| TriggerTimeRendered | String | The human-readable time when the alert was triggered. |
| TriggeredAlerts | Integer | The number of alerts triggered for this fired alert instance. |