Turn any search into a saved search via Splunk Web. You can also save search by editing savedsearches.conf. Test your searches before you save them.
via Splunk WebRefine the search until you consider it worthy. If you want to limit your search to a specific time period, add a modifier such as daysago::1 or hoursago::4. See the search reference.
Note: Many complex, long running searches may slow down your Splunk instance. Make sure you optimize your searches before saving them in a saved search.
Save your Search

Note: All admin level users see all saved searches, whether the user who created it explicitly shared it or not.
Edit saved searches at any time by clicking on the Admin link in the upper right hand corner. Select the Saved Searches link.
Schedule a saved searchOptionally schedule your Saved Search to run on a schedule by clicking the Schedules & Alerts link.
To turn your search into an alert, see set up alerts via Splunk Web.
Comments
No comments have been submitted.