increase value of artifact_offset of a savedsearch



Would like to use artifact_offset in to troubleshoot why alert-when-rises-by-issue ( does not seem to work for a savedsearch alert. The max artifact_offset seems to be only 3 for that alert. Not able to find a way to increase it to a high value. It would be nice to have an Advanced_Edit option for updating the artifact_offset of a savedsearch

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

<P style=" text-align: center; "><span class="lia-inline-image-display-wrapper lia-image-align-center" ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

<FONT size="5"><FONT size="5" color="#FF00FF">Get the latest news and updates from the Splunk Community ...