<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert for newly created Report/Alert in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-Alert-for-when-a-user-newly-creates-Report-Alert/m-p/605119#M13256</link>
    <description>&lt;LI-CODE lang="markup"&gt;| rest splunk_server=local servicesNS/-/-/saved/searches/&lt;/LI-CODE&gt;&lt;P&gt;The updated field might be useful in this instance&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jul 2022 09:24:26 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-07-11T09:24:26Z</dc:date>
    <item>
      <title>How to create Alert for when a user newly creates Report/Alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-Alert-for-when-a-user-newly-creates-Report-Alert/m-p/605117#M13255</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to create an Alert which will trigger when any user created new alert or report in our environment. So could you please help me with suitable query for this.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 14:42:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-Alert-for-when-a-user-newly-creates-Report-Alert/m-p/605117#M13255</guid>
      <dc:creator>Sandy</dc:creator>
      <dc:date>2022-07-11T14:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for newly created Report/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-Alert-for-when-a-user-newly-creates-Report-Alert/m-p/605119#M13256</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rest splunk_server=local servicesNS/-/-/saved/searches/&lt;/LI-CODE&gt;&lt;P&gt;The updated field might be useful in this instance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 09:24:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-Alert-for-when-a-user-newly-creates-Report-Alert/m-p/605119#M13256</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-07-11T09:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for newly created Report/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-Alert-for-when-a-user-newly-creates-Report-Alert/m-p/605136#M13261</link>
      <description>&lt;P&gt;Thank you for this query, but it will show all the reports and alerts. Actually i want to create an alert which will trigger if any user create one alert or report in splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 11:14:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-Alert-for-when-a-user-newly-creates-Report-Alert/m-p/605136#M13261</guid>
      <dc:creator>Sandy</dc:creator>
      <dc:date>2022-07-11T11:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for newly created Report/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-Alert-for-when-a-user-newly-creates-Report-Alert/m-p/605138#M13262</link>
      <description>&lt;P&gt;As I said, you can use the updated field to determine whether it has been updated / created recently - start by building a search to find the report updates / creations you are interested in&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 11:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-Alert-for-when-a-user-newly-creates-Report-Alert/m-p/605138#M13262</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-07-11T11:48:36Z</dc:date>
    </item>
  </channel>
</rss>

