Splunk Enterprise Security

Error saving event-based detection. Missing detection_id for the detection=

BJ17
Explorer

Unable to update and save detections after upgrading to Splunk ES version 8.1.0. It says Detection ID is missing. 

BJ17_0-1751972052861.png

BJ17_2-1751972216889.png

 

Labels (2)
0 Karma

PrewinThomas
Motivator

@BJ17 

Could you try recreating one of your existing detections in the new ES App(8.1) and check if you’re able to update and save it successfully?

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

BJ17
Explorer

We can recreate the rules without errors. But I'm looking for a way without changing the rule name.

0 Karma

PrewinThomas
Motivator

@BJ17 

Currently, I don't think there is any built-in option to migrate older detections to the new versioning format(in ES 8.1) without encountering these errors..

As a workaround, can you manually add a UUID-style string as the detection_id for your existing detections in savedsearches.conf and test if this resolves the issue

Eg:
[detection_name]
detection_id = d6f2b006-0041-11ec-8885-acde48001122


Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

BJ17
Explorer

Thanks @PrewinThomas ,
Splunk ES is hosted in the cloud. So, we cannot update the savedsearches.conf as you have mentioned. 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...