FiredAlerts
Query a summary of fired alerts in Splunk, grouped by the saved search that triggered them.
Columns
| Name | Type | Description |
| Name [KEY] | String | The name of the saved search that the fired alerts belong to. |
| Id | String | The REST resource link for the fired alerts summary entry. |
| UpdatedAt | Datetime | Datetime of the last update of the fired alerts summary entry. |
| Author | String | The Splunk user that owns the fired alerts summary entry. |
| App | String | The Splunk app context where the fired alerts are shared. |
| CanList | Boolean | Indicates whether the entry can be listed by the user. |
| CanWrite | Boolean | Indicates whether the entry can be modified by the user. |
| Modifiable | Boolean | Indicates whether the entry can be modified. |
| Owner | String | The Splunk user that owns the entry. |
| ReadPermissions | String | Permissions to read this entry. |
| WritePermissions | String | Permissions to write to this entry. |
| Removable | Boolean | Indicates whether the entry can be removed. |
| Sharing | String | The entry sharing type. |
| TriggeredAlertCount | Integer | The number of times this alert has triggered. |
| IsStreamingAlert | Boolean | Indicates whether the alert is a streaming alert. |