Alerting

is it possible to disable the ability to create alerts on saved searches?

JensT
Communicator

Hello,

is is possible to remove/disable the possibility for users to configure alerts for saved searches?

Splunk 4.1.7

Regards,

Jens

araitz
Splunk Employee
Splunk Employee

You can disable the 'schedule_search' capability for a role or roles in authorize.conf. By default, users in the 'user' role cannot configure alerts, but power and admin users can.

Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...