Alerting

In Splunk 6.6, why has the "Schedule Window" setting for alert become non-intuitive for users?

ryandg
Communicator

After upgrading from 6.5 to 6.6, the "Schedule Window" parameter in Splunk Web was moved from being right below the cron schedule box to being hidden away under the settings --> alert and reporting --> edit --> advanced edit --> bottom of a long list of weird parameters.

This is entirely non-intuitive for our basic users, is there anyway to get it back to where it used to be?

reedmohn
Communicator

Could this be a permissions / rights issue?

On 6.5 (not 6.6) I got feedback from users they can't see the Schedule Window setting under "Edit".
These users have a role with the edit_search_schedule_window capability.
However, clicking the report name from under "Settings->Searches, reports and alerts" will show the box in the right place.

I, with my Admin role, can see the Schedule Window under the cron schedule box in all places I expect to see it.

0 Karma

ngerosa
Path Finder

Hi ryandg,
From the docs:
"Splunk Enterprise does not provide a means of downgrading to previous versions. If you need to revert to an older Splunk release, just reinstall it."

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...