Dashboards & Visualizations

User Maintained Lists

andrewkenth
Communicator

Is there a way that I can have user maintain a list of values and then drive searches off said lists that does not involve importing a new sourcetype? Some of the searches used by the user are fairly complex and allowing the users to edit the normal and entire search is not advisable.

What are some recommendations for addressing this?

Thanks!

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could store your lists in lookups, and use the Sideview Utils Lookup Updater to maintain them.

If the number of values is small you may also use macros and give certain roles permission to edit their values.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...