Alerting

is it possible to disable the ability to create alerts on saved searches?

Communicator

Hello,

is is possible to remove/disable the possibility for users to configure alerts for saved searches?

Splunk 4.1.7

Regards,

Jens

Splunk Employee
Splunk Employee

You can disable the 'schedule_search' capability for a role or roles in authorize.conf. By default, users in the 'user' role cannot configure alerts, but power and admin users can.