Alerting
Highlighted

Can't remove alerts properly

Engager

When I use the alert manager to remove an alert, the line related to the alert cannot be removed.
However, the alert action field is set to action=alert_deleted.

I've been encountering this problem since I upgrade my splunk version from 5.0.2 to 6.0. Can this be related ?

Tags (3)
Highlighted

Re: Can't remove alerts properly

Path Finder

I noticed this issue also on v6 but am yet to work out why it happens. I thought maybe it was due to a capability being required (in Splunk roles) but there doesn't seem to be anything relating to alerts in the available list. I'll post again if I work it out though not sure what it could be currently.

0 Karma
Highlighted

Re: Can't remove alerts properly

Engager

I have the same issue:
http://answers.splunk.com/answers/128245/unable-to-delete-triggered-alerts.html

I haven't found a solution.

0 Karma