So i'm looking at the Splunk app for Windows infrastrucutre and data is populating great. Now I'm looking to set up some alerts for the results that I see, and I'm having trouble finding the actual query used to populate these dashboards.
There is no 'Edit Source' selection so that I can look through the XML, though when I dig through the HTML on the back end I get lost in java scripts and I see no actual query.
Is there a way to find these queries?
I'm looking at 'Group Changes' Dashboard within the App for Windows infrastructure.
There's no good way to find these without following the code.