Alerting

Alerts not showing in Content Management after cloned from Searches, Reports, and Alerts.

GIA
Path Finder

Hello,

I had to rename a bunch of rules yesterday so I cloned them from the Searches, Reports, and Alerts dashboard. They all have global permissions (all apps). For some reason I can't find none of the rules under the Content Management section. Is there a reason why the cloned rules aren't showing there?

Thanks!

 

Labels (1)
0 Karma

datadevops
Path Finder

Hi there,

Global Rules vs. App-Specific:

  • Cloned rules inherit the original rule's permission scope. Since you mentioned "global permissions (all apps)," they wouldn't show up under specific apps in Content Management.

Search for Global Rules:

  • Try searching for the rule names directly in the Content Management search bar. This should catch global rules regardless of their location.

Alternative View:

  • Navigate to Settings > Advanced Search > Manage Global Alerts/Dashboards/Reports. This section specifically lists globally-shared content.

Remember:

  • If you still can't find the rules, double-check their names and ensure they weren't accidentally deleted.

~ If the reply helps, a Karma upvote would be appreciated

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...