December 2014
Beginner to intermediate
344 pages
7h 34m
English
When using Splunk Web (again, I recommend this), you can edit all the alert properties in a single place.
Navigate to Settings | Searches, reports, and alerts; you can locate the search/alert and click on the name. From here, Splunk shows you and allows you to edit all the information for this alert. In addition, there are a few extended functionalities, as follows:
Splunk acceleration is a technique that Splunk uses to speed up searches which take a long time to complete, because they have to cover a large amount of data. You can enable acceleration for the search that your alert is based on by checking the Accelerate this search checkbox and selecting ...
Read now
Unlock full access