When I use the alert manager to remove an alert, the line related to the alert cannot be removed.
However, the alert action field is set to action=alert_deleted.
I've been encountering this problem since I upgrade my splunk version from 5.0.2 to 6.0. Can this be related ?
I have the same issue:
I haven't found a solution.
I noticed this issue also on v6 but am yet to work out why it happens. I thought maybe it was due to a capability being required (in Splunk roles) but there doesn't seem to be anything relating to alerts in the available list. I'll post again if I work it out though not sure what it could be currently.