Dashboards & Visualizations

Making Saved Searches Searchable

tkwaller
Builder

Hello

This may be a dumb question but I have a large list of saved searches that I am organizing in navigation menus. There are some that support uses that are already created but after organizing them, when you select one to open, it opens to results but the search bar is not available to edit the search.

What I would like to do is have saved searches and when support selects one to open, from the lists/nested lists I created for them, it opens and allows them to enter needed data. For example I saved a very basic search, (index=tt brokerId= listingId=), they can select it from the dropdown list I organized it into. Once it opens they could be able to enter the value for "brokerId" as well as "listingId" without extra typing or clicks.

Any ideas on how I could accomplish this or what I am doing incorrectly?
Thank you in advance!

0 Karma

lguinn2
Legend

I would consider using forms for this purpose.

Form Examples

Macros would also be a possibility, but forms are easier to use.

0 Karma

tkwaller
Builder

I understand that I could use a form but it wouldn't make much sense to create one for every search that support may use, there could be more than 100. I can organize saved searches into navigation menus using match commands, you can select and run those searches from the navigation menus, but when you do there is no way to edit the search from there. Is there a way that this can be accomplished? It would be much simpler if they could save theyre own searches, the navigation menus organize them, and all they have to do is select the search they want to run, change a little data and its done.

0 Karma

lguinn2
Legend

What version of Splunk?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...