Docs » Introduction to alerts and detectors in Splunk Observability Cloud » Use and customize AutoDetect alerts and detectors » Copy and customize an AutoDetect detector

Copy and customize an AutoDetect detector 🔗

To customize an AutoDetect detector you must copy it first, because AutoDetect detectors are read-only. When you customize an AutoDetect detector, Splunk Observability Cloud creates a copy of the original detector for you to apply the customizations.

  • Any changes you make to the customized detector don’t apply to the original AutoDetect detector.

  • Customized detectors created from AutoDetect detectors count toward the maximum numbers of detectors your organization can have. To learn more about the detectors limit, see Maximum number of detectors per organization.

  • The default limit for customized detectors per AutoDetect detector is 15. If you want to increase this limit, contact support for help.

To customize a copy of an AutoDetect detector, do the following:

  1. In the navigation menu, select Alerts & Detectors.

  2. Select the Detectors tab.

  3. In the search field, enter the name of the detector you want to customize.

    For example, to search for the “K8s Node Memory Utilization is high” detector, enter “K8s Node.” The result lists update automatically.

    This screenshot shows what an searching for an AutoDetect looks like on the Alerts page.
  4. Select the detector you want to customize to open it.

  5. Select Create a Customized Version.

  6. Make your customizations. For the full list of customizable arguments for each AutoDetect detector, see List of available AutoDetect detectors.

  7. Rename your customized detector to distinguish it from the original detector and any other copy.

  8. Select Activate.

Customized detectors created from AutoDetect detectors are marked with a Custom badge.

This page was last updated on Oct 17, 2024.