Reporting

Is it possible to escape whitespace in savedsearches?

nick405060
Motivator

As a workaround to https://answers.splunk.com/answers/761034/slack-alert-not-sending.html, I've used a single space " " as an specific alert parameter to fix the issue. Therefore the parameter in savedsearches looks like

action.slack.param.message =  

However upon reboot, that space gets wiped (which disables the Slack alert per 761034).

My question is...

How do you specify whitespace in savedsearches so it doesn't get wiped on reboot?

0 Karma

nick405060
Motivator

This is a terribly inelegant answer and I truly hope someone posts a better answer. But it works. Must have the blank line after. Not sure how you do this is you want a specific whitespace character.

action.slack.param.message = \

alert.digest_mode = 0
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...