Alerting

In Splunk 6.6, why has the "Schedule Window" setting for alert become non-intuitive for users?

ryandg
Communicator

After upgrading from 6.5 to 6.6, the "Schedule Window" parameter in Splunk Web was moved from being right below the cron schedule box to being hidden away under the settings --> alert and reporting --> edit --> advanced edit --> bottom of a long list of weird parameters.

This is entirely non-intuitive for our basic users, is there anyway to get it back to where it used to be?

reedmohn
Communicator

Could this be a permissions / rights issue?

On 6.5 (not 6.6) I got feedback from users they can't see the Schedule Window setting under "Edit".
These users have a role with the edit_search_schedule_window capability.
However, clicking the report name from under "Settings->Searches, reports and alerts" will show the box in the right place.

I, with my Admin role, can see the Schedule Window under the cron schedule box in all places I expect to see it.

0 Karma

ngerosa
Path Finder

Hi ryandg,
From the docs:
"Splunk Enterprise does not provide a means of downgrading to previous versions. If you need to revert to an older Splunk release, just reinstall it."

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...