Alerting

Unable to Remove Slack Alert From the Slack Alerts Configuration Page

Simon1
Engager

Hi,

I mistakenly cloned an alert to the "Slack Alerts" app instead of the normal "Search & Reporting" app. 

This alert is functioning and sending Slack messages when triggered. But the alert is in the wrong app.

But worse is that the alert now appears in the "All Configurations" page.

I am able to disable the alert but not able to remove it and I really need to remove it from the "All Configurations" page. I'm also not able to edit the alert in any way.

Is it possible to remove the alert from the "All Configurations" page?

RemoveSplunkSlackAlert.png

 

Thank you.

Labels (2)
0 Karma
1 Solution

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Simon1 

I feel there is not direct way to change the app context in UI also you are using splunk cloud.

otherway is go to searches reports and alerts from settings 

SanjayReddy_0-1701139898383.png

from their click on edit alet and clone 

SanjayReddy_1-1701139971532.png

then you can change the app context  and , once clone the alert delete the alert with app in slack context

SanjayReddy_2-1701139998753.png

 

View solution in original post

0 Karma

Simon1
Engager

Hi @SanjayReddy ,

That worked!

I was able to go to Searches Reports & Alerts from settings and delete the alert from there.

Thank you so much for your help!

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Simon1 

I feel there is not direct way to change the app context in UI also you are using splunk cloud.

otherway is go to searches reports and alerts from settings 

SanjayReddy_0-1701139898383.png

from their click on edit alet and clone 

SanjayReddy_1-1701139971532.png

then you can change the app context  and , once clone the alert delete the alert with app in slack context

SanjayReddy_2-1701139998753.png

 

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...