Splunk Enterprise Security

Error saving event-based detection. Missing detection_id for the detection=

BJ17
Explorer

Unable to update and save detections after upgrading to Splunk ES version 8.1.0. It says Detection ID is missing. 

BJ17_0-1751972052861.png

BJ17_2-1751972216889.png

 

Labels (2)
0 Karma

PrewinThomas
Motivator

@BJ17 

Could you try recreating one of your existing detections in the new ES App(8.1) and check if you’re able to update and save it successfully?

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

BJ17
Explorer

We can recreate the rules without errors. But I'm looking for a way without changing the rule name.

0 Karma

PrewinThomas
Motivator

@BJ17 

Currently, I don't think there is any built-in option to migrate older detections to the new versioning format(in ES 8.1) without encountering these errors..

As a workaround, can you manually add a UUID-style string as the detection_id for your existing detections in savedsearches.conf and test if this resolves the issue

Eg:
[detection_name]
detection_id = d6f2b006-0041-11ec-8885-acde48001122


Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

BJ17
Explorer

Thanks @PrewinThomas ,
Splunk ES is hosted in the cloud. So, we cannot update the savedsearches.conf as you have mentioned. 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...