I have about 50 splunk alerts with various descriptions. I would like to update the description by adding the word Splunk to the beginning of the description. Is there a way to accomplish this without going into the UI for each alert and renaming the alert?
You can use your favorite text editor to modify the appropriate savedsearches.conf file then restart Splunk. The file to modify depends on the app in which your alerts are defined. It will be $SPLUNK_HOME/etc/apps/myapp/local/savedsearches.conf.
--- If this reply helps you, an upvote would be appreciated.