Documentation: 3.2.3
Print Version Contents
This page last updated: 04/22/08 04:04pm

Set up saved searches

Turn any search into a saved search via Splunk Web. You can also save search by editing savedsearches.conf. Test your searches before you save them.

via Splunk Web

Refine the search until you consider it worthy. If you want to limit your search to a specific time period, add a modifier such as daysago::1 or hoursago::4. See the search reference.

Note: Many complex, long running searches may slow down your Splunk instance. Make sure you optimize your searches before saving them in a saved search.

Save your Search

  • Click on the drop-down arrow next to the search bar:

http://www.splunk.com/assets/doc-images/30_admin7_savesearchweb/savesearch.jpg

  • Select Save search...
  • Then, fill in the options presented on the save search screen.

http://www.splunk.com/assets/doc-images/3_2setupsavedsearches/ssearch.jpg

  • Give your saved search a name.
  • Pick a role to share your search with, or leave the drop down as Don't share.
  • Optionally add the saved search to any existing dashboard.
  • Click the Save button.

Note: All admin level users see all saved searches, whether the user who created it explicitly shared it or not.

Edit saved searches at any time by clicking on the Admin link in the upper right hand corner. Select the Saved Searches tab:

http://www.splunk.com/assets/doc-images/30_admin7_savesearchweb/editsearch.jpg

Schedule a saved search

Optionally schedule your Saved Search to run on a schedule by clicking the Schedules & Alerts link.

  • Click Run this search on a schedule to enable scheduling.
  • Pick basic or cron to specify a schedule for your search.

To turn your search into an alert, see set up alerts via Splunk Web.

Comments

No comments have been submitted.

Log in to comment.