saved search

noun

A search a user has made available for later use.

Saved searches can be set up to be run on a regular schedule, such as every ten minutes, every two hours, or every Monday at 10pm. These scheduled searches can be set up to generate alerts when the results of scheduled search runs meet particular conditions.

Saved searches are used as the basis for dashboard panels. Dashboard panels display the results of a search in the form of an event list, table, single value, or chart (chart panels are powered by searches that include reporting commands).

Saved, scheduled searches are also used to populate summary indexes.

Saved searches are a type of knowledge object that can be created and edited via Manager.

For more information

In the Knowledge Manager Manual:

In the Alerting Manual:

In the Data Visualizations Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time