<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Saved Searches not editable after upgrade to 10.2.X version in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Saved-Searches-not-editable-after-upgrade-to-10-2-X-version/m-p/759324#M23991</link>
    <description>&lt;P&gt;Hi community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm searching for your help.&lt;/P&gt;&lt;P&gt;After the Splunk version upgrade from 10.0.1 to 10.2.1, I can't edit my alerts and other saved searches. Do any one have seen this behavior?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 15 Mar 2026 10:29:39 GMT</pubDate>
    <dc:creator>herguzav</dc:creator>
    <dc:date>2026-03-15T10:29:39Z</dc:date>
    <item>
      <title>Saved Searches not editable after upgrade to 10.2.X version</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Saved-Searches-not-editable-after-upgrade-to-10-2-X-version/m-p/759324#M23991</link>
      <description>&lt;P&gt;Hi community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm searching for your help.&lt;/P&gt;&lt;P&gt;After the Splunk version upgrade from 10.0.1 to 10.2.1, I can't edit my alerts and other saved searches. Do any one have seen this behavior?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2026 10:29:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Saved-Searches-not-editable-after-upgrade-to-10-2-X-version/m-p/759324#M23991</guid>
      <dc:creator>herguzav</dc:creator>
      <dc:date>2026-03-15T10:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches not editable after upgrade to 10.2.X version</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Saved-Searches-not-editable-after-upgrade-to-10-2-X-version/m-p/759325#M23992</link>
      <description>I haven’t seen things, but please check the next items.&lt;BR /&gt;Which license you have? If you have changed from trial to free the you haven’t alerts anymore.&lt;BR /&gt;Have you check and ensure that owner for splunk files are correctly set?</description>
      <pubDate>Sun, 15 Mar 2026 12:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Saved-Searches-not-editable-after-upgrade-to-10-2-X-version/m-p/759325#M23992</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-03-15T12:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches not editable after upgrade to 10.2.X version</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Saved-Searches-not-editable-after-upgrade-to-10-2-X-version/m-p/759326#M23993</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the&amp;nbsp;Splunk "Enterprise Term License - No Enforcement (6.5 )" license and the owner al the splunk files are correct but still I can't edit my own alerts.&lt;/P&gt;&lt;P&gt;Do you have any other suggestion?&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2026 12:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Saved-Searches-not-editable-after-upgrade-to-10-2-X-version/m-p/759326#M23993</guid>
      <dc:creator>herguzav</dc:creator>
      <dc:date>2026-03-15T12:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches not editable after upgrade to 10.2.X version</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Saved-Searches-not-editable-after-upgrade-to-10-2-X-version/m-p/759334#M23996</link>
      <description>&lt;P&gt;And you are sure that there there are not too many license violations?&lt;/P&gt;&lt;P&gt;One thing which I also try is stop your splunk and change all file to splunk:splunk ownership. At least with older versions there are time by time when update leaves wrong ownerships especially if you are using tar package instead of rpm/dep.&lt;/P&gt;&lt;P&gt;If those didn't help then you should explain more deeper level what you have (os, version, single node, distributed etc.).&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 07:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Saved-Searches-not-editable-after-upgrade-to-10-2-X-version/m-p/759334#M23996</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-03-16T07:30:27Z</dc:date>
    </item>
  </channel>
</rss>

