Saving searches
If you are using reports, also referred to as "saved searches," in the Splunk Dashboard Studio see Use reports and saved searches with ds.savedSearch in the Splunk Dashboard Studio manual.
To learn more using ad hoc searches see Create search-based visualizations with ds.search in the Splunk Dashboard Studio manual.
When you create a search, you have several options to choose from to save the search. In the Search app, the choices are listed under the Save As drop-down.
Save as option | Description | More information |
---|---|---|
Report | When you create a search that you would like to run again, you can save the search as a report. | See Create and edit reports in the Reporting Manual.
If you are using reports, also referred to as "saved searches," in the Splunk Dashboard Studio, see Use reports and saved searches with ds.savedSearch in the Splunk Dashboard Studio manual for information on how to use them. |
Dashboard panel | You can also save a search as a dashboard panel. Dashboards can have one or more panels which can show search results in tables or in graphical visualizations. | See Getting started in the Dashboards and Visualizations manual. These searches are also referred to as "ad hoc" searches. If you are using these searches in the Splunk Dashboard Studio, see, Create search-based visualizations with ds.search in the Splunk Dashboard Studio manual. |
Alert | Some searches provide timely information that you want to be notified about. You can save a search as an alert. An alert is an action that a saved search triggers, based on the results of the search. The action might be to send an email or run a script. | See About alerts in the Alerting Manual. |
Event type | You can save a search as an event type. Event types are a categorization system to help you make sense of your data. Event types let you sift through huge amounts of data, find similar patterns, and create alerts and reports. | See About event types in the Knowledge Manager Manual. |
See Also
Manage Splunk Enterprise jobs from the OS | Scheduling searches |
This documentation applies to the following versions of Splunk® Enterprise: 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.3.0, 9.3.1
Feedback submitted, thanks!