Hi, I’m looking for a way to migrate Splunk cloud alerts (saved searches) from one environment to another.
For my case, the queries only require changing a single field, but the current process forces me to manually recreate each alert.
Is there a supported method or tool to:
Export saved searches/alerts from Environment A (e.g., via REST API, savedsearch, export, or configuration bundle).
Modify the query field.
Import them into Environment B without manually recreating each alert?
Thanks,
Sagarika
Hi there,
if all your saved searches are in the same app ACS is your friend https://help.splunk.com/en/splunk-cloud-platform/administer/admin-config-service-manual/9.3.2411/adm...
Hope this helps ...
Cheers, MuS