Splunk Search

How to List objects of an application

somesoni2
Revered Legend

I have an apps which has views, saved searches, field extractions and macros. Is it possible to list all the objects of an app using splunk search??

Basically I want to know if Splunk stores the app's metadata in any of the indexes.
Thanks in advance.

Tags (2)
0 Karma
1 Solution

lguinn2
Legend

Splunk does not store knowledge objects in any index. Knowledge objects are contained in .conf files and .xml files that are stored in the directory hierarchy under $SPLUNK_HOME/etc

Shameless promotion: there is an app on Splunkbase called X-ray Splunk which collects information about the knowledge objects and presents it in a variety of dashboards. It doesn't seem to work yet on all OSes, but it is free.

View solution in original post

0 Karma

jaxjohnny2000
Builder

Take a look at this splunk base app: https://splunkbase.splunk.com/app/2871/

0 Karma

lguinn2
Legend

Splunk does not store knowledge objects in any index. Knowledge objects are contained in .conf files and .xml files that are stored in the directory hierarchy under $SPLUNK_HOME/etc

Shameless promotion: there is an app on Splunkbase called X-ray Splunk which collects information about the knowledge objects and presents it in a variety of dashboards. It doesn't seem to work yet on all OSes, but it is free.

0 Karma

somesoni2
Revered Legend

Thanks for you response roberts. I was looking for more of a search query to list that which can be displayed over a dashboard.

0 Karma

rroberts
Splunk Employee
Splunk Employee

Also, from the Manager->Apps menu you can click the "view objects" link and sort the objects under that app.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...