Alerting

Splunk alerts have disappeared

aedelsteinpr
New Member

Our system has a few Splunk alerts set up and about a week ago, they all disappeared. They are not shown in the list of alerts inside Splunk and they are not carrying out their assigned actions.

If I try to create a new alert, it does not show up. I'll fill out the fields, save it, not see any error but then when I look at the list of alerts, it's not there:

alt text

However, it I try to create another alert with the same title as the alert I've just created, I receive an error, "Unable to create saved search with name [name]. A saved search with that name already exists."

Where are my alerts and how can I re-enable them? I'm using Splunk Enterprise v7.1.2.

0 Karma

somesoni2
Revered Legend

In the filters, for "App:" select all apps and try. Right now it's trying to look for alerts created in app "Home".

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...