Alerting

Help me out how to download all the rules/usecases in splunk

mputtam
Path Finder

Hi community,

Currently we are having 82 active rules/use cases in splunk and few of them were disabled. I was trying to pull the report of all the 82 rules but i couldn't able to do. I would requesting you to help me out on this...?

Thanks in advance,
Kishore. 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You don't say where are finding 82 so I can't advise about the difference.

The status of each alert is in the "disabled" field.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Start with this query then add a table command to display the fields you care about.

| rest /servicesNS/-/-/saved/searches splunk_server=local 
| search alert_type!="always" 

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

mputtam
Path Finder

Hi  @richgalloway  

Thanks for you hear back...!

The below mentioned quire is showing 182 rules but i could see in the setting only 82. is there something we have to add..?
can we get the status (ie enabled or disabled) on this...?

Thanks,
Kishore

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...