I have contacted Splunk support and here's their reply.
There was not a design change in 6.6x, it's more kind of bug fixing in newer version. Before with the old manager saved search page there was no way of knowing if what you were editing was an alert or a report so all options for alert_type were displayed. It was more of a bug that you could select alert_type = always and then set other attributes that made the saved search an alert vs a scheduled report. Ideally what the old ui would of done is if the user selected alert_type = always the other attributes would be limited so the user could only create a scheduled search not an alert. It would be appropriate to add "always" to the drop down. But **it doesn't makes sense that an alert would have alert_type = always, an alert needs a reason to trigger. A scheduled saved search that always triggers should be a scheduled report not an alert. The current behavior seen in 6.6x enables distinction between alerts and reports and the their respective properties. alert_type = always is for scheduled reports and does not need to appear in the workflow for creating/editing alerts.
Basically, the removal of alert_type=always is not a bug, it's more of design change. Hope it will help clear doubt for people like me. 🙂
... View more