Getting Data In

I have 100 alerts configured with certain condition, I have to change the condition but don't want to go to every alert and change the condition instead change in 1 place and it should change in all the places

amit2301
New Member

I have 100 alerts configured with certain condition, I have to change the condition but don't want to go to every alert and change the condition instead change in 1 place and it should change in all the places

Tags (2)
0 Karma

cmerriman
Super Champion

the fastest way that i've found is to go into the savedsearches.conf and find all the stanzas that you need to change and do a find and replace.

http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Alert/Configuringalertsinsavedsearches.conf

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.