Alerting

Alerts not showing in Content Management after cloned from Searches, Reports, and Alerts.

GIA
Path Finder

Hello,

I had to rename a bunch of rules yesterday so I cloned them from the Searches, Reports, and Alerts dashboard. They all have global permissions (all apps). For some reason I can't find none of the rules under the Content Management section. Is there a reason why the cloned rules aren't showing there?

Thanks!

 

Labels (1)
0 Karma

datadevops
Path Finder

Hi there,

Global Rules vs. App-Specific:

  • Cloned rules inherit the original rule's permission scope. Since you mentioned "global permissions (all apps)," they wouldn't show up under specific apps in Content Management.

Search for Global Rules:

  • Try searching for the rule names directly in the Content Management search bar. This should catch global rules regardless of their location.

Alternative View:

  • Navigate to Settings > Advanced Search > Manage Global Alerts/Dashboards/Reports. This section specifically lists globally-shared content.

Remember:

  • If you still can't find the rules, double-check their names and ensure they weren't accidentally deleted.

~ If the reply helps, a Karma upvote would be appreciated

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...