Is it possible to escape whitespace in savedsearches?


As a workaround to, I've used a single space " " as an specific alert parameter to fix the issue. Therefore the parameter in savedsearches looks like

action.slack.param.message =  

However upon reboot, that space gets wiped (which disables the Slack alert per 761034).

My question is...

How do you specify whitespace in savedsearches so it doesn't get wiped on reboot?

0 Karma


This is a terribly inelegant answer and I truly hope someone posts a better answer. But it works. Must have the blank line after. Not sure how you do this is you want a specific whitespace character.

action.slack.param.message = \

alert.digest_mode = 0
0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...