<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Managing many alerts simultaneously in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/617608#M14439</link>
    <description>&lt;P&gt;Splunk does not offer a sane means to manage Alerts in great numbers at all. The User Interface is vacant of assistance in this regard, a large list that makes no effort to show the last edited row - leaving the user to fumble through, choosing the same item repeatedly or missing items easily. Splunk relies on the Browser for basic navigation functionality between pages but did not consider users' needs when navigating and working with mechanisms more bespoke. I hope this comment resonates with someone at Splunk to address this, because it is a big deal and the product in its current state is ripe for disruption.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Oct 2022 23:03:56 GMT</pubDate>
    <dc:creator>bac</dc:creator>
    <dc:date>2022-10-18T23:03:56Z</dc:date>
    <item>
      <title>Am I able to edit many alerts simultaneously?</title>
      <link>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/355435#M6285</link>
      <description>&lt;P&gt;I am currently managing 50 alerts and this number will multiply in the next couple of weeks. Editing my alerts is cumbersome. If I want to change a common property, I have to change every single instance by itself. Is there a way to change an alert property like its permissions, or triggers, for multiple alerts at a time?&lt;BR /&gt;I have looked at "Alert Manager", but it seems to be tailored to managing incidents, not the actual alerts in of itself.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 02:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/355435#M6285</guid>
      <dc:creator>sebkue</dc:creator>
      <dc:date>2022-10-19T02:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Managing many alerts simultaneously</title>
      <link>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/355436#M6286</link>
      <description>&lt;P&gt;Hi @sebkue&lt;/P&gt;

&lt;P&gt;If you have access to the file system, you could make bulk changes to saved searches through the config files.&lt;BR /&gt;
Permissions can be found in &lt;CODE&gt;[$SPLUNK_HOME$]\etc\apps\[your app]\metadata\local.meta&lt;/CODE&gt;.  The admin manual page is &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Defaultmetaconf"&gt;here&lt;/A&gt;&lt;BR /&gt;
All other search attributes (action, email, search string, etc.) can be found in  &lt;CODE&gt;[$SPLUNK_HOME$]\etc\apps\[your app]\local\savedsearches.conf.&lt;/CODE&gt;  The admin manual page is &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Savedsearchesconf"&gt;here&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;It's not the most elegant way, but I'm not aware of any way to make bulk changes within the UI.&lt;/P&gt;

&lt;P&gt;Hope that helps.  &lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 20:44:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/355436#M6286</guid>
      <dc:creator>LCM_BRogerson</dc:creator>
      <dc:date>2017-11-08T20:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Managing many alerts simultaneously</title>
      <link>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/355437#M6287</link>
      <description>&lt;P&gt;I do not have access to the file system. Is there a reason that bulk editing alerts is not a feature?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 09:12:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/355437#M6287</guid>
      <dc:creator>sebkue</dc:creator>
      <dc:date>2017-11-10T09:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: Managing many alerts simultaneously</title>
      <link>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/617608#M14439</link>
      <description>&lt;P&gt;Splunk does not offer a sane means to manage Alerts in great numbers at all. The User Interface is vacant of assistance in this regard, a large list that makes no effort to show the last edited row - leaving the user to fumble through, choosing the same item repeatedly or missing items easily. Splunk relies on the Browser for basic navigation functionality between pages but did not consider users' needs when navigating and working with mechanisms more bespoke. I hope this comment resonates with someone at Splunk to address this, because it is a big deal and the product in its current state is ripe for disruption.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 23:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/617608#M14439</guid>
      <dc:creator>bac</dc:creator>
      <dc:date>2022-10-18T23:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Managing many alerts simultaneously</title>
      <link>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/617609#M14440</link>
      <description>&lt;P&gt;Please also note that the Permissions Dialog intermittently closes itself with or without interaction, when it does so with interaction the outcome is erroneous - it seems you made a change but no change was made. The list does not put any effort into showing that a change was or wasn't made nor which item you were last editing. Highly vulnerable to human error.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 23:06:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/617609#M14440</guid>
      <dc:creator>bac</dc:creator>
      <dc:date>2022-10-18T23:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Managing many alerts simultaneously</title>
      <link>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/617612#M14441</link>
      <description>&lt;P&gt;The Permissions Dialog will also occasionally open without content, only showing the close (x), CANCEL, and SAVE button but not responding to them. It seems that clicking outside of the Dialog or forcing a browser refresh is the only way out of that erroneous state. Managing Alerts is really in the 3rd World of Internet.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 23:52:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Am-I-able-to-edit-many-alerts-simultaneously/m-p/617612#M14441</guid>
      <dc:creator>bac</dc:creator>
      <dc:date>2022-10-18T23:52:12Z</dc:date>
    </item>
  </channel>
</rss>

