I have two SPlunk consoles - one has alerting, the other does not. How do I add alerting to the one that doesn't have it. I do not have "Save as Alert"
Hi @IG1690,
as @FelixLeh said, if you have the same permissions, both the instances can save searches as alert, if you haven't the only reason can be that your role hasn't the grants to do this.
if instead the problem is that one system cannot send eMail you have to go in [Settings -- Server Settings -- Email Settings] and setup your email server.
ciao.
Giuseppe
Are the both full enterprise versions? Free version cannot create alerts.
Do both User Accounts on each of the Splunk Instances have the same Permissions? (eg. User,Power,Admin)
If one of the Roles/Users does not have sufficient Permissions to create Alerts it could be the reason for the problem.
I hope this helps!
_______________________________________
If this was helpful please consider awarding Karma. Thx!