Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

Unable to enable summary indexing for the alert from Splunk UI

rkumarkm
Engager

Hello Splunkers, 

 I'm unable to change the summary indexing value from false to true for the newly created alerts from Splunk UI.

It is only working, when the savedsearch.conf is edited from CLI.

Alert >> Edit >> Advanced edit >>action.summary_index = false

 

Thank you in advance.

0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @rkumarkm 

Its not possible to set an *Alert* to output to a summary index using the UI, however it is possible to set a *Report* to save into a summary index via the UI.

First you need to schedule the report, click the dropdown next to the report name and select "Edit schedule" - Configure the report to be scheduled. Once its schedule the dropdown will now give an "Edit summary indexing" option - clicking on this enables the modal to configure the summary indexing:

livehybrid_0-1754730811426.png

 

If you also require alert actions then you can add these by going to "Edit Schedule" in the dropdown and clicking the Trigger Actions tab:

livehybrid_1-1754730864351.png

 

Note: the exact naming of tabs/modals/links may differ between versions - the above are from 10.0

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @rkumarkm 

Its not possible to set an *Alert* to output to a summary index using the UI, however it is possible to set a *Report* to save into a summary index via the UI.

First you need to schedule the report, click the dropdown next to the report name and select "Edit schedule" - Configure the report to be scheduled. Once its schedule the dropdown will now give an "Edit summary indexing" option - clicking on this enables the modal to configure the summary indexing:

livehybrid_0-1754730811426.png

 

If you also require alert actions then you can add these by going to "Edit Schedule" in the dropdown and clicking the Trigger Actions tab:

livehybrid_1-1754730864351.png

 

Note: the exact naming of tabs/modals/links may differ between versions - the above are from 10.0

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...