Splunk Search

Is it possible to add the same action to all of the alerts in one time?

sarit_s
Communicator

Hello

I need to add alert action to many alerts,
Is it possible to add the same action to all of the alerts in one time ?

 

Thanks

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

No, it is not possible.

I would do it once in the UI, then edit savedsearches.conf in the relevant app and copy the changes to the other alerts.  Then restart the SH.  If you have a SHC, make the changes on the deployer and apply the shbundle.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...