Hello Splunkers,
I'm unable to change the summary indexing value from false to true for the newly created alerts from Splunk UI.
It is only working, when the savedsearch.conf is edited from CLI.
Alert >> Edit >> Advanced edit >>action.summary_index = false
Thank you in advance.
Hi @rkumarkm
Its not possible to set an *Alert* to output to a summary index using the UI, however it is possible to set a *Report* to save into a summary index via the UI.
First you need to schedule the report, click the dropdown next to the report name and select "Edit schedule" - Configure the report to be scheduled. Once its schedule the dropdown will now give an "Edit summary indexing" option - clicking on this enables the modal to configure the summary indexing:
If you also require alert actions then you can add these by going to "Edit Schedule" in the dropdown and clicking the Trigger Actions tab:
Note: the exact naming of tabs/modals/links may differ between versions - the above are from 10.0
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Hi @rkumarkm
Its not possible to set an *Alert* to output to a summary index using the UI, however it is possible to set a *Report* to save into a summary index via the UI.
First you need to schedule the report, click the dropdown next to the report name and select "Edit schedule" - Configure the report to be scheduled. Once its schedule the dropdown will now give an "Edit summary indexing" option - clicking on this enables the modal to configure the summary indexing:
If you also require alert actions then you can add these by going to "Edit Schedule" in the dropdown and clicking the Trigger Actions tab:
Note: the exact naming of tabs/modals/links may differ between versions - the above are from 10.0
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing