Documentation: 3.3
Print Version Contents
This page last updated: 07/11/08 01:07pm

Save options

You can save any of your searches, schedule your saved searches, and define alert conditions for your scheduled searches. For more information, refer to the User Manual topic about Save, schedule, and alert options.

Save a search

Search for the trade_app_logouts events in the sampledata:

index=sampledata eventtype=trade_app_logoutsSearch

To save a search:

1. Click on the search bar menu.

2. Select Save search... from the menu.
The Save Search dialog box opens.

3. In the "Search options" tab, name your search. (In 3.3, this is Search.)

4. Click Save.

Note: When saving your search, you can choose to add it to one or more dashboards.

Splunk lets you delete or modify your saved searches and add them to the dashboard. For more information on how to manage saved searches, refer to the User Manual's Save, Schedule, and Alert page.

Schedule the search

From the search bar menu:

1. Choose Save search...

2. Click the Schedule & Alerts tab. (In 3.3, this is Schedule and Alert.)

3. Under Schedule, check "Run this search on a schedule".

Note: You can define the schedule frequency with the Basic or Cron options.

Schedule an alert

After you schedule a search, you can define alert conditions based on thresholds in the number of events, sources, and hosts in your results. You can receive these alerts via RSS feed or email.

You can also trigger a shell script, such as a script to generate an SNMP trap or call an API to send the event to another system. If you need additional email options (like setting the From: address) see the Alerts page in the Admin manual.

Previous: Event types    |    Next: Reports

Comments

No comments have been submitted.

Log in to comment.