Admin Manual

 


How Splunk Works

Set up saved searches

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Set up saved searches

Turn any search into a saved search via Splunk Web. You can also save search by editing savedsearches.conf. Test your searches before you save them.


via Splunk Web

Refine the search until you consider it worthy. If you want to limit your search to a specific time period, add a modifier such as daysago:1 or hoursago:4. See the search reference.


Note: Many complex, long running searches may slow down your Splunk instance. Make sure you optimize your searches before saving them in a saved search.


Save your Search


30 admin7 savesearchweb-savesearch.jpg


3 2setupsavedsearches-ssearch.jpg


Note: All admin level users see all saved searches, whether the user who created it explicitly shared it or not.


Edit saved searches at any time by clicking on the Admin link in the upper right hand corner. Select the Saved Searches tab:


30 admin7 savesearchweb-editsearch.jpg


Schedule a saved search

Optionally schedule your Saved Search to run on a schedule by clicking the Schedules & Alerts link.


To turn your search into an alert, see set up alerts via Splunk Web.

This documentation applies to the following versions of Splunk: 3.2 , 3.2.1 , 3.2.2 , 3.2.3 , 3.2.4 , 3.2.5 , 3.2.6 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!