Splunk Enterprise

How to easily copy alerts to another instance?

larrywest
Explorer

Using Splunk Enterprise (currently 7.3.x here); I'm not an admin, so cannot see/change "savedsearches.conf".

I have over a dozen alerts (with more to come) that I need to copy from our pre-production Splunk search head to production (where I would edit the details).

I would expect a simple "export" menu choice somewhere in the Alerts page or on a particular Alert, but there's nothing remotely similar.

The Splunk "apps" already exist on both, and differ, so I couldn't ask some admin to just copy it.

Given that the search terms, cron schedule, time span, trigger condition, and actions are all separate, it is a major amount of work to copy & paste (with multiple additional clicks). 

 

Labels (1)

larrywest
Explorer

PS: I sincerely suggest that a product manager (or equivalent) at Splunk try doing this, in person, for several non-trivial alerts (with multiple actions).

It is a very common, error-prone, and much complained-about activity at our site.

isoutamo
SplunkTrust
SplunkTrust

Have you check if this is already proposed on ideas.splunk.com? If not, maybe you should add it there!

r. Ismo

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...