Alerting

Bulk Update recipient email addresses for alerts.

cmahan
Path Finder

Is there a way to update the recipient email addresses on multiple alerts at once? Our domain has changed and I need all @xxxx.com emails changed to @yyyyyy.com without having to edit hundreds of individual alerts manually.

0 Karma
1 Solution

sanjay_shrestha
Contributor

Yes. It can be done modifying (globoal replacement) savedsearches.conf.

View solution in original post

vermabhi90
Explorer

looking for answer.

0 Karma

sanjay_shrestha
Contributor

Yes. It can be done modifying (globoal replacement) savedsearches.conf.

cmahan
Path Finder

Thanks! Exactly what I was looking for!

savedsearches.conf

0 Karma

chandrasekharko
Path Finder

Is it a global change or local change? A local change worked fine for me

0 Karma

vermabhi90
Explorer

Hi,

Please guide how you did it, I have to do same.

Thanks

0 Karma

rahulbhatia
Path Finder

Hi,

Can you please guide what change have you done in savedsearches.conf to get it done

Thanks in advance

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...