Documentation: 3.3.4
Print Version Contents
This page last updated: 11/20/08 02:11pm

Save options

You can save any of your searches, schedule your saved searches, and define alert conditions for your scheduled searches. For more information, refer to the User Manual topic about Save, schedule, and alert options.

Save a search

Search for the trade_app_logouts events in the sampledata:

index=sampledata eventtype=trade_app_logoutsSearch

To save a search:

1. Click on the search bar menu.

2. Select Save search... from the menu.
The Save Search dialog box opens.

3. In the "Search options" tab, name your search. (In 3.3, this is Search.)

4. Click Save.

Note: When saving your search, you can choose to add it to one or more dashboards.

Splunk lets you delete or modify your saved searches and add them to the dashboard. For more information on how to manage saved searches, refer to the User Manual's Find and manage saved searches page.

Schedule the search

From the search bar menu:

1. Choose Save search...

2. Click the Schedule & Alerts tab. (In 3.3, this is Schedule and Alert.)

3. Under Schedule, check "Run this search on a schedule".

Note: You can define the schedule frequency with the Basic or Cron options.

Schedule an alert

After you schedule a search, you can define alert conditions based on thresholds in the number of events, sources, and hosts in your results. You can receive these alerts via RSS feed or email.

You can also trigger a shell script, such as a script to generate an SNMP trap or call an API to send the event to another system. If you need additional email options (like setting the From: address) see the Alerts page in the Admin manual.

Previous: Event types    |    Next: Reports

Comments

  1. rmaus: corrected--thanks for the tip!

  2. Clicking on "User Manual's Save, Schedule, and Alert" link in "Save a search" section gives "Page not found". As a work-around, clicking on "Save, schedule, and alert options" in "Save options" section (presumably) gives desired result.

Log in to comment.