Alerting

Where are alerts stored in Linux directory structure?

BrendanCO
Path Finder

Hello. I had to move my entire old Splunk directory to a new filesystem for archiving as it was pretty hosed. Did a reinstall back to /opt/splunk and have just been setting it all up again. I created some pretty specific alerts previously that I would like to see if I can just copy over from the old instance. Does anyone know where those are stored?

somesoni2
Revered Legend

Alerts are basically saved searches that executes an actions, so just look for savedsearches.conf files in $Splunk_home/etc/apps/<appname>/local, $Splunk_home/etc/apps/<appname>/default and $Splunk_home/etc/users/<username>/<appname>/local

BrendanCO
Path Finder

Awesome. Looking through them (there were like 10 instances of that file), I found the ones I needed. I just copied $OldSPlunk/etc/users/admin/search/local/savedsearches.conf to #Splunk_home/etc/users/admin/search/local/savedsearches.conf and it worked like a charm! Thanks a lot somesoni2!

aoleske
Path Finder

Very helpful, thank you!

0 Karma
Get Updates on the Splunk Community!

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering. Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...