Hello,
is is possible to remove/disable the possibility for users to configure alerts for saved searches?
Splunk 4.1.7
Regards,
Jens
You can disable the 'schedule_search' capability for a role or roles in authorize.conf. By default, users in the 'user' role cannot configure alerts, but power and admin users can.