Frequently asked questions

This section provides answers to common questions about alerts and incidents.

Note: In the Controlled Availability release stage, Splunk products may have limitations on customer access, features, maturity, and regional availability. For additional information on Controlled Availability please contact your Splunk representative.

Common questions

What is the difference between an alert and an incident?
An alert is a single signal, while an incident groups related alerts into one issue.
Can I manually create an incident?
No. Currently incidents are automatically created by the system.
Can I reopen a closed incident?
No. Closed incidents cannot be reopened; new related alerts will trigger a new incident.