<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: renaming saved alerts in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23145#M4095</link>
    <description>&lt;P&gt;I really can't believe that since 2011 there is still no option to rename only the Alert title via the GUI... Is this so hard to be done?&lt;/P&gt;</description>
    <pubDate>Thu, 22 Mar 2018 15:10:02 GMT</pubDate>
    <dc:creator>tsvetan</dc:creator>
    <dc:date>2018-03-22T15:10:02Z</dc:date>
    <item>
      <title>renaming saved alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23142#M4092</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have a lot of saved searches and alerts. To make it easier to browse, I want rename them. &lt;/P&gt;

&lt;P&gt;If I go to manage searches and reports and click on the search name, I'm able to only change the "Search" string. &lt;BR /&gt;
A possible solution I found is to clone it and then just edit the "search name" string &amp;amp; delete the previous search.&lt;/P&gt;

&lt;P&gt;Is this method good? I just don't want to be blamed by the whole department for spoiling the system!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2012 19:23:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23142#M4092</guid>
      <dc:creator>aniketb</dc:creator>
      <dc:date>2012-08-01T19:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: renaming saved alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23143#M4093</link>
      <description>&lt;P&gt;You could edit the names directly in the appropriate config file rather than cloning and deleting.  Take a look at this.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/35617/rename-and-grouping-saved-searches"&gt;http://splunk-base.splunk.com/answers/35617/rename-and-grouping-saved-searches&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2012 19:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23143#M4093</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-08-01T19:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: renaming saved alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23144#M4094</link>
      <description>&lt;P&gt;While it is possible to edit the config file, you will need to restart Splunk to reread the configuration. This may be a factor to some people!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 19:31:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23144#M4094</guid>
      <dc:creator>ff_rumali</dc:creator>
      <dc:date>2017-10-04T19:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: renaming saved alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23145#M4095</link>
      <description>&lt;P&gt;I really can't believe that since 2011 there is still no option to rename only the Alert title via the GUI... Is this so hard to be done?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 15:10:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23145#M4095</guid>
      <dc:creator>tsvetan</dc:creator>
      <dc:date>2018-03-22T15:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: renaming saved alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23146#M4096</link>
      <description>&lt;P&gt;I am unable to access the URL. Getting a 500 Internal Server Error. &lt;BR /&gt;
Also, I believe my profile type is 'user' and am not sure if i can access the config file. Would love to find a way where a business user can edit saved alerts rather than having to touch a config file.&lt;BR /&gt;
Any updates or insights from anyone? &lt;BR /&gt;
thank you&lt;/P&gt;</description>
      <pubDate>Fri, 13 Apr 2018 15:04:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/23146#M4096</guid>
      <dc:creator>kamalanc</dc:creator>
      <dc:date>2018-04-13T15:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: renaming saved alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/515956#M144905</link>
      <description>&lt;P&gt;Restarting splunk is not required.&lt;/P&gt;&lt;P&gt;It is enough to refresh the config.&lt;/P&gt;&lt;P&gt;To reload your endpoints type the following into your browser:&lt;/P&gt;&lt;DIV class="samplecode"&gt;&lt;PRE&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Rename-and-grouping-saved-searches/td-p/28279" target="_blank" rel="nofollow noopener noreferrer"&gt;http://&amp;lt;yoursplunkserver&amp;gt;:8000/en-US/debug/refresh&lt;/A&gt;&lt;/PRE&gt;&lt;P&gt;Ref:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Configurationfilechangesthatrequirerestart#When_to_restart_splunkd" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Configurationfilechangesthatrequirerestart#...&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 25 Aug 2020 07:47:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/renaming-saved-alerts/m-p/515956#M144905</guid>
      <dc:creator>pellegrini</dc:creator>
      <dc:date>2020-08-25T07:47:28Z</dc:date>
    </item>
  </channel>
</rss>

