Splunk Search

Plan searches for future events

The_dark_side_o
Explorer

Hello everybody,

Is there a configuration file that an application(written on my own) can edit to plan searches? What I need is to plan searches for retrieving event coming in the future. And, if this file exist, it is possible to set searches to start automatically?

0 Karma

Ayn
Legend

savedsearches.conf is where you can define and schedule searches. http://docs.splunk.com/Documentation/Splunk/latest/Admin/Savedsearchesconf

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...