Reporting

Is it possible to escape whitespace in savedsearches?

nick405060
Motivator

As a workaround to https://answers.splunk.com/answers/761034/slack-alert-not-sending.html, I've used a single space " " as an specific alert parameter to fix the issue. Therefore the parameter in savedsearches looks like

action.slack.param.message =  

However upon reboot, that space gets wiped (which disables the Slack alert per 761034).

My question is...

How do you specify whitespace in savedsearches so it doesn't get wiped on reboot?

0 Karma

nick405060
Motivator

This is a terribly inelegant answer and I truly hope someone posts a better answer. But it works. Must have the blank line after. Not sure how you do this is you want a specific whitespace character.

action.slack.param.message = \

alert.digest_mode = 0
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...