Alerting

I can't change "action.summary_index" to enable summary indexing in alert.

yutaka1005
Builder

My Splunk Ver : 8.0.2

I want enable summary indexing in alert, so I've tried change "action.summary_index" to true from advanced edit by according to below documents.

https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Updatealerts#Enable_summary_indexing

But when I click save button, it return to "false", and there isn't some error message.

Is someone know about it?

Labels (1)

karapet
New Member

After I changed action.summary_index to true in savedsearches.conf, I got the error when attempted to modify again the alert on the UI 'scheduled search action=summary_index is not supported with per result alerting', which in my case makes sense, as my alert had this kind of 'multiline' results. So you might be able to convert your alert to trigger 'once' instead for each result depending on your case.

0 Karma

adonio
Ultra Champion

what exactly do you want to do?
if you want to write the data of the alert to a splunk index, use the Log Event option and choose the place (index) you want the data to be at. read here more:
http://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/LogEvents

0 Karma

yutaka1005
Builder

@adonio

Thank you for comment.
I want to write alert result to summary index, and also I know that collect command make it possible.

I just want to know why I can't change action.summary_index option on GUI.
Is it issue? or specification?

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...