Reporting

Rename saved search

skippylou
Communicator

So it appears that you can't rename a saved search through splunkweb. All the other parts seem to be editable, but not the name it is referenced as. I'm currently getting around this by cloning then deleting the original saved search.

Is there a way that I am missing? If not, how does one go about submitting a feature request?

Thanks,

scott

Tags (2)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

You are correct, you can not change the name of a savedsearch object. Partly this is to discourage situations where objects are referenced in other places (e.g., views, navs, other searches), as objects are referenced by name.

The recommended way of dealing with this is what you've been doing, which is to clone the object, then, if you have resolved dependencies, delete the original.

It would be nice if the nav menus could use the "description" field or something like that, as that probably would make this less of an issue in the first place.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

You are correct, you can not change the name of a savedsearch object. Partly this is to discourage situations where objects are referenced in other places (e.g., views, navs, other searches), as objects are referenced by name.

The recommended way of dealing with this is what you've been doing, which is to clone the object, then, if you have resolved dependencies, delete the original.

It would be nice if the nav menus could use the "description" field or something like that, as that probably would make this less of an issue in the first place.

Brian_Osburn
Builder

I'd think if you modified the savedsearches.conf you should be able to change it that way..

To open an enhancement request, go to the support page https://www.splunk.com/page/submit_issue and submit a P4 enhancement request..

Brian

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Problem with this is that it requires both access to the server and a restart of Splunk.

0 Karma

skippylou
Communicator

Yeah, was looking for users to be able to do it that don't have shell access to the box.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...