<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are changes made to savedsearch not reflecting in Splunk Web or .conf files, but it displays as updated via API? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-changes-made-to-savedsearch-not-reflecting-in-Splunk-Web/m-p/299907#M56724</link>
    <description>&lt;P&gt;I see the error in my ways....Since I had no context of App, rather than updating the saved search under a particular app, the REST call was creating a new saved search under the "search" app....Logging in as admin to splunk web made this very clear....Context is everything I suppose.&lt;/P&gt;</description>
    <pubDate>Thu, 18 May 2017 13:41:35 GMT</pubDate>
    <dc:creator>oclumbertruck</dc:creator>
    <dc:date>2017-05-18T13:41:35Z</dc:date>
    <item>
      <title>Why are changes made to savedsearch not reflecting in Splunk Web or .conf files, but it displays as updated via API?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-changes-made-to-savedsearch-not-reflecting-in-Splunk-Web/m-p/299906#M56723</link>
      <description>&lt;P&gt;Howdy folks,&lt;/P&gt;

&lt;P&gt;I've got a saved search that has 4 emails specified in action.email.to.  This is correct looking in the saved search edit portion of splunk web, and the advanced edit.&lt;/P&gt;

&lt;P&gt;If I query for the saved search via the REST API, the addresses are correct.  I have a script that grabs the value of action.email.to for the given saved search, and then append another email address, and posts to the appropriate url.  This seems to work just fine.  If I do a GET against the saved search, it displays 5 email addresses.&lt;/P&gt;

&lt;P&gt;However in Splunk Web, the saved search only displays the 4 addresses, as well as only 4 addresses in the advanced edit under action.email.to.  If I check the savedsearches.conf, it has the 4 addresses....I've tried _bump, debug/reset, and restarting splunk, API still displayed 5 addresses, but 4 everywhere else.&lt;/P&gt;

&lt;P&gt;What gives?&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 20:27:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-changes-made-to-savedsearch-not-reflecting-in-Splunk-Web/m-p/299906#M56723</guid>
      <dc:creator>oclumbertruck</dc:creator>
      <dc:date>2017-05-17T20:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why are changes made to savedsearch not reflecting in Splunk Web or .conf files, but it displays as updated via API?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-changes-made-to-savedsearch-not-reflecting-in-Splunk-Web/m-p/299907#M56724</link>
      <description>&lt;P&gt;I see the error in my ways....Since I had no context of App, rather than updating the saved search under a particular app, the REST call was creating a new saved search under the "search" app....Logging in as admin to splunk web made this very clear....Context is everything I suppose.&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 13:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-changes-made-to-savedsearch-not-reflecting-in-Splunk-Web/m-p/299907#M56724</guid>
      <dc:creator>oclumbertruck</dc:creator>
      <dc:date>2017-05-18T13:41:35Z</dc:date>
    </item>
  </channel>
</rss>

