<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to convert a scheduled report to an alert?  (6.6.3) in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308097#M5550</link>
    <description>&lt;P&gt;I ran into the same thing and as far as I can tell the only option is to recreate it as an alert which you already know about. &lt;/P&gt;

&lt;P&gt;I did find this in my searching though I'm not sure if it helps any:  &lt;A href="https://answers.splunk.com/answers/187134/report-vs-alert-whats-the-difference.html"&gt;https://answers.splunk.com/answers/187134/report-vs-alert-whats-the-difference.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2017 18:41:55 GMT</pubDate>
    <dc:creator>kmaron</dc:creator>
    <dc:date>2017-09-05T18:41:55Z</dc:date>
    <item>
      <title>Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308086#M5539</link>
      <description>&lt;P&gt;If a saved search is initially created as an alert, I get the option to "Edit alert". But if it's saved as a report, that option is not there and Edit Schedule does not offer the same options. I can't see any way to modify a report to have a conditional alert. I can schedule a report. And I can assign an email action to a report. But the GUI offers no way to assign a conditional action to a report. In order to get the conditional verbiage, I have to recreate the saved search explicitly as an alert. Or edit config files directly.&lt;/P&gt;

&lt;P&gt;The new paradigm of reports vs alerts is not ... handy. Maybe I'm just not used to it. &lt;/P&gt;

&lt;P&gt;v6.6.3, Linux&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 23:30:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308086#M5539</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2017-08-28T23:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308087#M5540</link>
      <description>&lt;P&gt;Hi twinspop,&lt;BR /&gt;
reports and alerts are different expressions of a search (eventually the same).&lt;BR /&gt;
If the problem is to have a condition in the execution of a scheduled report, you can put this condition in your search: e.g. I have a report that lists all the non updated devices, but sometimes there is an error in the ingestion of the device situation, so in this case in my list there are thousands of not updated devices.&lt;BR /&gt;
So I inserted in my search the condition &lt;CODE&gt;| where count&amp;lt;1000&lt;/CODE&gt; (usually there are few not updated devices) so I'm sure that it doesn't send a wrong report when there is a not updated situation, but only a correct one when situation is updated.&lt;BR /&gt;
I hope I was clear.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 07:08:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308087#M5540</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-29T07:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308088#M5541</link>
      <description>&lt;P&gt;This is no longer accurate with Splunk 6.6.x.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 13:08:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308088#M5541</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2017-08-29T13:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308089#M5542</link>
      <description>&lt;P&gt;You have to find a different condition to verify your report execution.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 13:16:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308089#M5542</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-29T13:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308090#M5543</link>
      <description>&lt;P&gt;No, the interface is totally different. If you have 6.6.x you will see.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 13:26:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308090#M5543</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2017-08-29T13:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308091#M5544</link>
      <description>&lt;P&gt;Sorry but I explained badly:&lt;BR /&gt;
you have to insert a condition in your search, something like &lt;CODE&gt;| where count&amp;lt;1000&lt;/CODE&gt; but relevant for your search.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 14:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308091#M5544</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-29T14:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308092#M5545</link>
      <description>&lt;P&gt;If you're not running 6.6.x you don't understand. For REPORTS there is only an option to send an email when the report runs. Period. There is no qualifier for number of results returned, custom eval, or anything else. Even with "where count&amp;gt;0" i will still get email on every run regardless of results. In 6.6 REPORTS are inherently different from ALERTS and I don't see anyway to convert one way or the other.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 14:59:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308092#M5545</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2017-08-29T14:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308093#M5546</link>
      <description>&lt;P&gt;You have to insert the additional condition in the search used in report, in other words:&lt;BR /&gt;
if original search is&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=my_index | stats dc(host) AS count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;you have to modify search (not report conditions)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=my_index | stats dc(host) AS count | where count&amp;lt;1000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 15:03:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308093#M5546</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-29T15:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308094#M5547</link>
      <description>&lt;P&gt;Doesn't work in 6.6&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 15:05:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308094#M5547</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2017-08-29T15:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308095#M5548</link>
      <description>&lt;P&gt;I downvoted this post because not answering the question. extra search commands are not leading to the subject at hand: how to change a report to an alert in 6.6&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 15:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308095#M5548</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2017-08-29T15:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308096#M5549</link>
      <description>&lt;P&gt;You cannotconvert a report in an alert, this is a running workaround that I used.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 15:11:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308096#M5549</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-29T15:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308097#M5550</link>
      <description>&lt;P&gt;I ran into the same thing and as far as I can tell the only option is to recreate it as an alert which you already know about. &lt;/P&gt;

&lt;P&gt;I did find this in my searching though I'm not sure if it helps any:  &lt;A href="https://answers.splunk.com/answers/187134/report-vs-alert-whats-the-difference.html"&gt;https://answers.splunk.com/answers/187134/report-vs-alert-whats-the-difference.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 18:41:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308097#M5550</guid>
      <dc:creator>kmaron</dc:creator>
      <dc:date>2017-09-05T18:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308098#M5551</link>
      <description>&lt;P&gt;I think I found the answer.  In your Searches, reports, and alerts, go to Edit &amp;gt; Advanced Edit &amp;gt; &lt;/P&gt;

&lt;P&gt;change "alert_type" from "always" to "number of events".&lt;BR /&gt;&lt;BR /&gt;
set "alert_comparator" to "greater than"&lt;BR /&gt;
set "alert_threshold" to "0"&lt;/P&gt;

&lt;P&gt;Save and schedule your search (if you haven't already).  At this point, you should be able to click Edit and see "Edit Alert" and the saved search will show up under the Alerts filter at the top instead of Reports&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:16:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308098#M5551</guid>
      <dc:creator>matt_park</dc:creator>
      <dc:date>2020-09-29T16:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308099#M5552</link>
      <description>&lt;P&gt;Nice. I mean, this still seems to be a bug to me, but nice workaround. :thumbs-up:&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 23:51:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308099#M5552</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2017-10-18T23:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308100#M5553</link>
      <description>&lt;P&gt;Agree - super annoying&lt;/P&gt;

&lt;P&gt;To add to the above solution. The search must also be scheduled for the above to work.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 18:33:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308100#M5553</guid>
      <dc:creator>pj</dc:creator>
      <dc:date>2018-02-08T18:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to convert a scheduled report to an alert?  (6.6.3)</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308101#M5554</link>
      <description>&lt;P&gt;This solution doesn't seem to be working now. After Edit, I don't see any Advanced Edit. &lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 06:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-a-way-to-convert-a-scheduled-report-to-an-alert-6-6-3/m-p/308101#M5554</guid>
      <dc:creator>bhavya49</dc:creator>
      <dc:date>2019-11-27T06:55:16Z</dc:date>
    </item>
  </channel>
</rss>

