Splunk Search

Plan searches by editing configuration files

The_dark_side_o
Explorer

Hello everybody,

is there a way to plan searches by editing a configuration file? Usually I plan searches through splunk web, setting start time, ending time, alerts and etc...now I want to do the same thing writing the searches into a config file. It is possible?

0 Karma

dart
Splunk Employee
Splunk Employee

Yes, It's savedsearches.conf

The_dark_side_o
Explorer

Ok, but I want to do this allowing an application(written on my own) to edit a config file. Is this file "savedsearches.conf"?

0 Karma

The_dark_side_o
Explorer

Ok, but I want to do this allowing an application(written on my own) to edit a config file. Is this file "savedsearches.conf"?

0 Karma

Ayn
Legend

Sounds like what you want is a saved search? http://docs.splunk.com/Documentation/Splunk/5.0.2/Tutorial/Saveasearch

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...