<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create Alert in Cloud version of Splunk in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712738#M3613</link>
    <description>&lt;P&gt;Is the search a newly formed search or an edited Report? There should be an option for "Alert" when you make a new search and press "Save As", even in cloud.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Feb 2025 20:24:58 GMT</pubDate>
    <dc:creator>marnall</dc:creator>
    <dc:date>2025-02-27T20:24:58Z</dc:date>
    <item>
      <title>How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712726#M3612</link>
      <description>&lt;P&gt;There is no option "Alert" when I try to "Save As" for current search. There is also no "Access Controls" in "Settings".&lt;/P&gt;&lt;P&gt;My final plan is to send alerts to Slack channels, but all the instructions I was able to find are for different versions of Splunk (Enterprise etc). Could someone point me in a right direction?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 18:27:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712726#M3612</guid>
      <dc:creator>Evgeny197</dc:creator>
      <dc:date>2025-02-27T18:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712738#M3613</link>
      <description>&lt;P&gt;Is the search a newly formed search or an edited Report? There should be an option for "Alert" when you make a new search and press "Save As", even in cloud.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 20:24:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712738#M3613</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2025-02-27T20:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712744#M3614</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Evgeny197_0-1740688978700.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34740iD4F71930C2002DCF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Evgeny197_0-1740688978700.png" alt="Evgeny197_0-1740688978700.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is what I see&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 20:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712744#M3614</guid>
      <dc:creator>Evgeny197</dc:creator>
      <dc:date>2025-02-27T20:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712745#M3615</link>
      <description>&lt;P&gt;It is a new search&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 20:43:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712745#M3615</guid>
      <dc:creator>Evgeny197</dc:creator>
      <dc:date>2025-02-27T20:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712748#M3617</link>
      <description>&lt;P&gt;Are you able to check if your user has a role with the schedule_search capability?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 21:03:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712748#M3617</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2025-02-27T21:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712750#M3618</link>
      <description>&lt;P&gt;How can I check that? "Settings" does not have it it seems&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Evgeny197_0-1740690435594.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34741i52DEF5D01E9D4C23/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Evgeny197_0-1740690435594.png" alt="Evgeny197_0-1740690435594.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 21:07:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712750#M3618</guid>
      <dc:creator>Evgeny197</dc:creator>
      <dc:date>2025-02-27T21:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712838#M3619</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Obviously you have normal user role or some non power/admin user role.&lt;/P&gt;&lt;P&gt;In normal case only admin or power user can create and run alerts.&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263556"&gt;@marnall&lt;/a&gt;&amp;nbsp;said you must have correct capability to create alerts. You should ask that from your Splunk Admins which may give it to you or not. That depends on your company policy who can create and run those.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 15:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712838#M3619</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-02-28T15:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712844#M3620</link>
      <description>&lt;P&gt;Hi Ismo,&lt;/P&gt;&lt;P&gt;Thank you! I came to that conclusion yesterday and contacted the admins.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Evgeny&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 16:21:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712844#M3620</guid>
      <dc:creator>Evgeny197</dc:creator>
      <dc:date>2025-02-28T16:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712847#M3621</link>
      <description>Please mark some answer as Solution, so other people will see it later and get help!</description>
      <pubDate>Fri, 28 Feb 2025 16:29:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/712847#M3621</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-02-28T16:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/740827#M3637</link>
      <description>&lt;P&gt;Hello Ismo,&lt;/P&gt;&lt;P&gt;I am able to create an alert, but it does not send the alerts to Slack.&lt;/P&gt;&lt;P&gt;I did check that the Slack Alert Setup has an updated "Slack App OAuth Token".&lt;/P&gt;&lt;P&gt;Are there any steps I am missing?&lt;/P&gt;&lt;P&gt;(By the way, if I chose email instead of Slack the alerts go through)&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 19:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/740827#M3637</guid>
      <dc:creator>Evgeny197</dc:creator>
      <dc:date>2025-03-04T19:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Alert in Cloud version of Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/740838#M3639</link>
      <description>I haven’t use slack alert action, so I just give general hints.&lt;BR /&gt;Usually alert actions are written some log what happened into _internal index you should try to found something which is related to it.</description>
      <pubDate>Tue, 04 Mar 2025 20:48:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-create-Alert-in-Cloud-version-of-Splunk/m-p/740838#M3639</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-03-04T20:48:55Z</dc:date>
    </item>
  </channel>
</rss>

