Alerting

Alerts not showing in Content Management after cloned from Searches, Reports, and Alerts.

GIA
Path Finder

Hello,

I had to rename a bunch of rules yesterday so I cloned them from the Searches, Reports, and Alerts dashboard. They all have global permissions (all apps). For some reason I can't find none of the rules under the Content Management section. Is there a reason why the cloned rules aren't showing there?

Thanks!

 

Labels (1)
0 Karma

datadevops
Path Finder

Hi there,

Global Rules vs. App-Specific:

  • Cloned rules inherit the original rule's permission scope. Since you mentioned "global permissions (all apps)," they wouldn't show up under specific apps in Content Management.

Search for Global Rules:

  • Try searching for the rule names directly in the Content Management search bar. This should catch global rules regardless of their location.

Alternative View:

  • Navigate to Settings > Advanced Search > Manage Global Alerts/Dashboards/Reports. This section specifically lists globally-shared content.

Remember:

  • If you still can't find the rules, double-check their names and ensure they weren't accidentally deleted.

~ If the reply helps, a Karma upvote would be appreciated

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...