This documentation does not apply to the most recent version of Splunk.
This documentation applies to the following versions of Splunk: 3.0
Please note: You can optionally schedule the Saved Search to run on a schedule by specifying either a basic or cron schedule. Saved searches for alerts usually have a time range specified, you can set your time range using modifiers like daysago:1 or starthoursago:4. See the search reference for more. You can also find a reference on cron schedules on this page.
You can edit saved searches at any time by clicking on the Admin link in the upper right hand corner, and then selecting the Saved Searches tab:
Saved searches are defined in savedsearches.conf. However, most modifications can be done through SplunkWeb.
You may wish to share saved searches via SplunkBase, or distribute them as bundles to other systems in your data center. Learn more about bundle files.