Splunk Search

renaming saved alerts

aniketb
Path Finder

Hi,

We have a lot of saved searches and alerts. To make it easier to browse, I want rename them.

If I go to manage searches and reports and click on the search name, I'm able to only change the "Search" string.
A possible solution I found is to clone it and then just edit the "search name" string & delete the previous search.

Is this method good? I just don't want to be blamed by the whole department for spoiling the system!

Tags (4)
1 Solution

sdaniels
Splunk Employee
Splunk Employee

You could edit the names directly in the appropriate config file rather than cloning and deleting. Take a look at this.

http://splunk-base.splunk.com/answers/35617/rename-and-grouping-saved-searches

View solution in original post

tsvetan
Explorer

I really can't believe that since 2011 there is still no option to rename only the Alert title via the GUI... Is this so hard to be done?

sdaniels
Splunk Employee
Splunk Employee

You could edit the names directly in the appropriate config file rather than cloning and deleting. Take a look at this.

http://splunk-base.splunk.com/answers/35617/rename-and-grouping-saved-searches

ff_rumali
Explorer

While it is possible to edit the config file, you will need to restart Splunk to reread the configuration. This may be a factor to some people!

pellegrini
Path Finder

Restarting splunk is not required.

It is enough to refresh the config.

To reload your endpoints type the following into your browser:

0 Karma

kamalanc
Engager

I am unable to access the URL. Getting a 500 Internal Server Error.
Also, I believe my profile type is 'user' and am not sure if i can access the config file. Would love to find a way where a business user can edit saved alerts rather than having to touch a config file.
Any updates or insights from anyone?
thank you

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...