Alerting

Alerts not showing in Content Management after cloned from Searches, Reports, and Alerts.

GIA
Path Finder

Hello,

I had to rename a bunch of rules yesterday so I cloned them from the Searches, Reports, and Alerts dashboard. They all have global permissions (all apps). For some reason I can't find none of the rules under the Content Management section. Is there a reason why the cloned rules aren't showing there?

Thanks!

 

Labels (1)
0 Karma

datadevops
Path Finder

Hi there,

Global Rules vs. App-Specific:

  • Cloned rules inherit the original rule's permission scope. Since you mentioned "global permissions (all apps)," they wouldn't show up under specific apps in Content Management.

Search for Global Rules:

  • Try searching for the rule names directly in the Content Management search bar. This should catch global rules regardless of their location.

Alternative View:

  • Navigate to Settings > Advanced Search > Manage Global Alerts/Dashboards/Reports. This section specifically lists globally-shared content.

Remember:

  • If you still can't find the rules, double-check their names and ensure they weren't accidentally deleted.

~ If the reply helps, a Karma upvote would be appreciated

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...