Alerting

Why can't I find the place to create an alert?

PVBsupport
New Member

I am running Splunk 6.1.3 and while in Search, in the New Search area, I have entered "EventCode=1001". A few entries arrive and I click on the Save As button and my only options are: Report
Dashboard Panel
----------------------------
Event Type

(I would include a picture but I don't have enough "karma points".)

From what I researched, there should be an Alert option below Dashboard Panel included in this area but there is no option given.

Please let me know how to create Alerts since this option isn't available within the "usual" method or a way to make the Alert option appear in the Save As drop down menu.

Tags (5)
0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Does your user role have the schedule_search capability? You can see in Settings > Access Controls > Roles, click on your role and find the list of capabilities down the page.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Does your user role have the schedule_search capability? You can see in Settings > Access Controls > Roles, click on your role and find the list of capabilities down the page.

ChrisG
Splunk Employee
Splunk Employee

Great! When you get the information you need from someone on Splunk Answers, please upvote/accept it. Welcome to Splunk!

0 Karma

PVBsupport
New Member

Hi Chris,

Thanks for your suggestion. You have solved my problem! I had to add my list of capabilities.

0 Karma
Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...