Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

Unable to enable summary indexing for the alert from Splunk UI

rkumarkm
Engager

Hello Splunkers, 

 I'm unable to change the summary indexing value from false to true for the newly created alerts from Splunk UI.

It is only working, when the savedsearch.conf is edited from CLI.

Alert >> Edit >> Advanced edit >>action.summary_index = false

 

Thank you in advance.

0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @rkumarkm 

Its not possible to set an *Alert* to output to a summary index using the UI, however it is possible to set a *Report* to save into a summary index via the UI.

First you need to schedule the report, click the dropdown next to the report name and select "Edit schedule" - Configure the report to be scheduled. Once its schedule the dropdown will now give an "Edit summary indexing" option - clicking on this enables the modal to configure the summary indexing:

livehybrid_0-1754730811426.png

 

If you also require alert actions then you can add these by going to "Edit Schedule" in the dropdown and clicking the Trigger Actions tab:

livehybrid_1-1754730864351.png

 

Note: the exact naming of tabs/modals/links may differ between versions - the above are from 10.0

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @rkumarkm 

Its not possible to set an *Alert* to output to a summary index using the UI, however it is possible to set a *Report* to save into a summary index via the UI.

First you need to schedule the report, click the dropdown next to the report name and select "Edit schedule" - Configure the report to be scheduled. Once its schedule the dropdown will now give an "Edit summary indexing" option - clicking on this enables the modal to configure the summary indexing:

livehybrid_0-1754730811426.png

 

If you also require alert actions then you can add these by going to "Edit Schedule" in the dropdown and clicking the Trigger Actions tab:

livehybrid_1-1754730864351.png

 

Note: the exact naming of tabs/modals/links may differ between versions - the above are from 10.0

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...