<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: delete multiple alerts from splunk cloud in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/delete-multiple-alerts-from-splunk-cloud/m-p/692765#M3125</link>
    <description>&lt;P&gt;It would help to know what curl command you tried and what error it returned.&lt;/P&gt;&lt;P&gt;AIUI, alerts must be deleted individually.&amp;nbsp; There is no method in the UI for selecting multiple alerts for deletion.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2024 13:23:47 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-07-09T13:23:47Z</dc:date>
    <item>
      <title>delete multiple alerts from splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/delete-multiple-alerts-from-splunk-cloud/m-p/692751#M3124</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I'm using Splunk cloud and i want to delete multiple alerts from list.&lt;/P&gt;&lt;P&gt;i was trying to do it with curl but got errors that i cannot figure out.&lt;/P&gt;&lt;P&gt;is there any other way ?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 11:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/delete-multiple-alerts-from-splunk-cloud/m-p/692751#M3124</guid>
      <dc:creator>sarit_s6</dc:creator>
      <dc:date>2024-07-09T11:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: delete multiple alerts from splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/delete-multiple-alerts-from-splunk-cloud/m-p/692765#M3125</link>
      <description>&lt;P&gt;It would help to know what curl command you tried and what error it returned.&lt;/P&gt;&lt;P&gt;AIUI, alerts must be deleted individually.&amp;nbsp; There is no method in the UI for selecting multiple alerts for deletion.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 13:23:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/delete-multiple-alerts-from-splunk-cloud/m-p/692765#M3125</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-07-09T13:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: delete multiple alerts from splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/delete-multiple-alerts-from-splunk-cloud/m-p/692852#M3128</link>
      <description>&lt;P&gt;ok so i was able to figure it out&lt;BR /&gt;but now i have new issue that i don't know even where to start&lt;/P&gt;&lt;P&gt;i have a list of alerts that i want to move from one splunk app to another&lt;/P&gt;&lt;P&gt;is there a way to do it with script ? because doing it one by one will take me forever.&lt;/P&gt;&lt;P&gt;i have a file with - alert name, alert id, current app name, new app name&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 06:19:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/delete-multiple-alerts-from-splunk-cloud/m-p/692852#M3128</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2024-07-10T06:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: delete multiple alerts from splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/delete-multiple-alerts-from-splunk-cloud/m-p/693055#M3134</link>
      <description>&lt;P&gt;If the apps are defined in a custom app (a Best Practice) then edit savedsearches.conf to put the alerts in another app.&amp;nbsp; Then upload and install both apps.&lt;/P&gt;&lt;P&gt;Otherwise, you can use the REST API to do the job.&amp;nbsp; See &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.2/RESTREF/RESTsearch#saved.2Fsearches.2F.7Bname.7D" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.2/RESTREF/RESTsearch#saved.2Fsearches.2F.7Bname.7D&lt;/A&gt;&lt;/P&gt;&lt;P&gt;First, I'd try modifying the eai:acl.app setting, but I'm not sure that's supported.&amp;nbsp; If it works, you're golden and just need to loop through a list of searches to move.&lt;/P&gt;&lt;P&gt;If that doesn't work then you're stuck with copy-and-delete.&amp;nbsp; Read the specs for each search, create a copy of it in the destination app, then delete the original.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 12:02:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/delete-multiple-alerts-from-splunk-cloud/m-p/693055#M3134</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-07-11T12:02:05Z</dc:date>
    </item>
  </channel>
</rss>

