Admin Manual

 


How Splunk Works

How Saved Searches Work

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

How Saved Searches Work

30 admin7 savesearchweb-allsearches.jpg


Set Up Saved Searches via SplunkWeb

30 admin7 savesearchweb-savesearch.jpg


Please note: You can optionally schedule the Saved Search to run on a schedule by specifying either a basic or cron schedule. Saved searches for alerts usually have a time range specified, you can set your time range using modifiers like daysago:1 or starthoursago:4. See the search reference for more. You can also find a reference on cron schedules on this page.


You can edit saved searches at any time by clicking on the Admin link in the upper right hand corner, and then selecting the Saved Searches tab:


30 admin7 savesearchweb-editsearch.jpg


Configuration files for saved searches and alerts

Saved searches are defined in savedsearches.conf. However, most modifications can be done through SplunkWeb.


You may wish to share saved searches via SplunkBase, or distribute them as bundles to other systems in your data center. Learn more about bundle files.

This documentation applies to the following versions of Splunk: 3.0 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.