<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can you alter the Splunk search used for an alert? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233160#M69205</link>
    <description>&lt;P&gt;In most cases, yes you can, as they are saved searches. The &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.4.1/User/SearchesReportsAlerts"&gt;Splunk Cloud User Manual&lt;/A&gt; is a great place to start, and there is also the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Alert/Aboutalerts"&gt;Alerting Manual&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 18 Aug 2016 22:07:33 GMT</pubDate>
    <dc:creator>dshpritz</dc:creator>
    <dc:date>2016-08-18T22:07:33Z</dc:date>
    <item>
      <title>Can you alter the Splunk search used for an alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233159#M69204</link>
      <description>&lt;P&gt;Can you alter the Splunk search used for an alert?  I don't see any way to alter it.&lt;/P&gt;

&lt;P&gt;I am being asked to choose a product.  From the About box in our local Splunk website, it lists Cloud, so I am selecting that.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2016 20:41:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233159#M69204</guid>
      <dc:creator>marnee</dc:creator>
      <dc:date>2016-08-18T20:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can you alter the Splunk search used for an alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233160#M69205</link>
      <description>&lt;P&gt;In most cases, yes you can, as they are saved searches. The &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.4.1/User/SearchesReportsAlerts"&gt;Splunk Cloud User Manual&lt;/A&gt; is a great place to start, and there is also the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Alert/Aboutalerts"&gt;Alerting Manual&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2016 22:07:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233160#M69205</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2016-08-18T22:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can you alter the Splunk search used for an alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233161#M69206</link>
      <description>&lt;P&gt;Sure! You are looking for &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Alert/UsingManagertoupdateandexpandalertfunctionality#Edit_an_alert_search"&gt;Edit an alert search&lt;/A&gt; in the &lt;EM&gt;Alerting Manual&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2016 23:06:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233161#M69206</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-08-18T23:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can you alter the Splunk search used for an alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233162#M69207</link>
      <description>&lt;P&gt;Is it possible to update the alert query without recreating the alert. When I edit the alert query it is not giving the option to "Save". It give the option to "Save As", that lead us to create a new alert.,Every time when I make the changes on alert query, it forced me to save as different query / different alert. Is there any way I can modify the existing query instead of creating different alert every time ?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 13:04:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233162#M69207</guid>
      <dc:creator>cstamilarasan</dc:creator>
      <dc:date>2020-04-17T13:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Can you alter the Splunk search used for an alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233163#M69208</link>
      <description>&lt;P&gt;If you have permissions, view the alert, click the edit button, choose Open in Search. Make the changes to the query and execute the search. You should then be able to click save.,&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 16:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233163#M69208</guid>
      <dc:creator>masonbanhammer</dc:creator>
      <dc:date>2020-04-23T16:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can you alter the Splunk search used for an alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233164#M69209</link>
      <description>&lt;P&gt;Yes, you just need to run the query after you make the edits, the save button should then be available&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 16:43:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233164#M69209</guid>
      <dc:creator>masonbanhammer</dc:creator>
      <dc:date>2020-04-23T16:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can you alter the Splunk search used for an alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233165#M69210</link>
      <description>&lt;P&gt;Thanks for this clear answer on my very old question (when I was a newbie).&lt;/P&gt;

&lt;P&gt;Splunk is awesome, but nothing is perfect. That way of altering the search query is so unintuitive that it still annoys me. Nobody I've worked with has ever been able to figure out how to edit a search query for an alert on their own. &lt;/P&gt;

&lt;P&gt;A person shouldn't have to go to a manual for such a basic operation.&lt;/P&gt;

&lt;P&gt;An improvement would be: Instead of "Open in Search", the text "Edit Search Query" would be much, much better. And then when it opens in Search, it should somehow look very different from normal search (e.g. different background color, make Save buttons much more prominent)&lt;/P&gt;

&lt;P&gt;Maybe one day when I'm feeling ambitious, I'll figure out how and will send a suggestion to Splunk for that change, but what's the point? Most companies don't listen to such suggestions, no matter how good a company (and so many companies are forgetting about usability and about intuitive and efficient UIs these days).&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 19:07:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/233165#M69210</guid>
      <dc:creator>marnee</dc:creator>
      <dc:date>2020-05-06T19:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can you alter the Splunk search used for an alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/593155#M206453</link>
      <description>&lt;P&gt;That total worked.&amp;nbsp; And wasn't intuitive...&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 18:21:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/593155#M206453</guid>
      <dc:creator>rogerdpack</dc:creator>
      <dc:date>2022-04-08T18:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can you alter the Splunk search used for an alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/598950#M208531</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/59065"&gt;@cstamilarasan&lt;/a&gt;&amp;nbsp;&amp;nbsp;You have to run the query after you edit it in order for the "Save" option to show.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It took me a while to figure that out.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 17:37:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-you-alter-the-Splunk-search-used-for-an-alert/m-p/598950#M208531</guid>
      <dc:creator>WillTheOnly</dc:creator>
      <dc:date>2022-05-23T17:37:38Z</dc:date>
    </item>
  </channel>
</rss>

