Alerting

In Splunk 6.6, why has the "Schedule Window" setting for alert become non-intuitive for users?

ryandg
Communicator

After upgrading from 6.5 to 6.6, the "Schedule Window" parameter in Splunk Web was moved from being right below the cron schedule box to being hidden away under the settings --> alert and reporting --> edit --> advanced edit --> bottom of a long list of weird parameters.

This is entirely non-intuitive for our basic users, is there anyway to get it back to where it used to be?

reedmohn
Communicator

Could this be a permissions / rights issue?

On 6.5 (not 6.6) I got feedback from users they can't see the Schedule Window setting under "Edit".
These users have a role with the edit_search_schedule_window capability.
However, clicking the report name from under "Settings->Searches, reports and alerts" will show the box in the right place.

I, with my Admin role, can see the Schedule Window under the cron schedule box in all places I expect to see it.

0 Karma

ngerosa
Path Finder

Hi ryandg,
From the docs:
"Splunk Enterprise does not provide a means of downgrading to previous versions. If you need to revert to an older Splunk release, just reinstall it."

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...