Alerting

In Splunk 6.6, why has the "Schedule Window" setting for alert become non-intuitive for users?

ryandg
Communicator

After upgrading from 6.5 to 6.6, the "Schedule Window" parameter in Splunk Web was moved from being right below the cron schedule box to being hidden away under the settings --> alert and reporting --> edit --> advanced edit --> bottom of a long list of weird parameters.

This is entirely non-intuitive for our basic users, is there anyway to get it back to where it used to be?

reedmohn
Communicator

Could this be a permissions / rights issue?

On 6.5 (not 6.6) I got feedback from users they can't see the Schedule Window setting under "Edit".
These users have a role with the edit_search_schedule_window capability.
However, clicking the report name from under "Settings->Searches, reports and alerts" will show the box in the right place.

I, with my Admin role, can see the Schedule Window under the cron schedule box in all places I expect to see it.

0 Karma

ngerosa
Path Finder

Hi ryandg,
From the docs:
"Splunk Enterprise does not provide a means of downgrading to previous versions. If you need to revert to an older Splunk release, just reinstall it."

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...