Alerting

How to create a shared alert via REST API

mlopesn
New Member

Hello everyone!

I had a great doubt about creating alerts using Splunk Rest API.

Every of them are shared only for the owner/creator after been created.

How can I create a shared alert with my group of users using the Rest API?

0 Karma

justinabrahms
New Member

You do this via a different endpoint than the alarm creation. My script:

```
curl -v -k -u "$SPLUNK_USER:$SPLUNK_PASSWORD" \
"https://$DOMAIN:8089/services/saved/searches/$ALARM_NAME/acl" \
--data-urlencode sharing="app" \
--data-urlencode output_mode="json" \
--data-urlencode owner="$SPLUNK_USER" \
--data-urlencode perms.read="" \
--data-urlencode perms.write="
"

```

This grants read and write permissions to everyone in the 'app' sharing thing.

0 Karma

justinabrahms
New Member

You do this via a different endpoint than the alarm creation. My script:

```
curl -v -k -u "$SPLUNK_USER:$SPLUNK_PASSWORD" \
"https://$DOMAIN:8089/services/saved/searches/$ALARM_NAME/acl" \
--data-urlencode sharing="app" \
--data-urlencode output_mode="json" \
--data-urlencode owner="$SPLUNK_USER" \
--data-urlencode perms.read="" \
--data-urlencode perms.write="
"

```

This grants read and write permissions to everyone in the 'app' sharing thing.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...