Splunk Version: 8.0.2007.1 Instance: Search Head App AIX or other apps Problem: After updating an alert's saved search, the saved search reverts after updating the alert's cron job or other settings. Nitty Gritty: This only occurs when the saved search is modified and saved in a different browser tab, and then, the alert is updated in the original tab where the alert is modified. Confused, don't worry, I have an example below. Example: User modifies saved search and cron job of alert in "two different browser tabs": User opens alert-1 in App in browser tab 1 User opens search in second tab (through right-click -> open in new tab) User updates search, runs search and then saves search under alert-1 name User closes search tab (tab 2) or leaves both tabs open User goes back to tab 1 to update cron job of alert (or other configuration on alert) User saves alert settings. User wants to verify that alert saved search is correct by opening up second tab (right-click on open in search -> new tab) User finds that search string has reverted to original search
... View more