Create and manage saved searches in Splunk Enterprise Security
Create a saved search, also called a scheduled report, in Splunk Enterprise Security.
- From the Enterprise Security menu bar, select Configure > Content Management.
- Click Create New Content and select Saved Search.
- Create a saved search, also called a scheduled report, following the instructions in the Splunk platform documentation.
- For Splunk Enterprise, see Create a new report in the Splunk Enterprise Reporting Manual.
- For Splunk Cloud, see Create a new report in the Splunk Cloud Reporting Manual.
- Modify the permissions of the report to share it with Enterprise Security so that you can view and manage the search in Enterprise Security, following the instructions in the Splunk platform documentation.
- For Splunk Enterprise, see Set report permissions in the Splunk Enterprise Reporting Manual.
- For Splunk Cloud, see Set report permissions in the Splunk Cloud Reporting Manual.
Create and manage key indicator searches in Splunk Enterprise Security | Create and manage search-driven lookups in Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Enterprise Security: 5.1.1
Feedback submitted, thanks!