Alerting

Help me out how to download all the rules/usecases in splunk

mputtam
Path Finder

Hi community,

Currently we are having 82 active rules/use cases in splunk and few of them were disabled. I was trying to pull the report of all the 82 rules but i couldn't able to do. I would requesting you to help me out on this...?

Thanks in advance,
Kishore. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You don't say where are finding 82 so I can't advise about the difference.

The status of each alert is in the "disabled" field.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Start with this query then add a table command to display the fields you care about.

| rest /servicesNS/-/-/saved/searches splunk_server=local 
| search alert_type!="always" 

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

mputtam
Path Finder

Hi  @richgalloway  

Thanks for you hear back...!

The below mentioned quire is showing 182 rules but i could see in the setting only 82. is there something we have to add..?
can we get the status (ie enabled or disabled) on this...?

Thanks,
Kishore

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...