Create and manage saved searches in Splunk Enterprise Security
Create a saved search, also called a scheduled report, in Splunk Enterprise Security.
- From the Enterprise Security menu bar, select Configure > Content Management.
- Click Create New Content and select Saved Search.
- Create a saved search, also called a scheduled report, following the instructions in the Splunk platform documentation.
- For Splunk Enterprise, see Create a new report in the Splunk Enterprise Reporting Manual.
- For Splunk Cloud, see Create a new report in the Splunk Cloud Reporting Manual.
Create and manage key indicator searches in Splunk Enterprise Security
Create and manage search-driven lookups in Splunk Enterprise Security
This documentation applies to the following versions of Splunk® Enterprise Security: 5.1.1