All Apps and Add-ons

Why i can't see "savedsearches.conf" both in splunk_TA_for windows and splunk_TA_for unix and linux?

AllandNothing
Engager

I can't understand this, all other stuff works great, i receive all the information i enabled, i have installed these apps both on forwarders and search heads, all that is missing is the "savedsearches.conf". I would appreciate suggestions because for the moment is very important to obtain these searches for me.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @AllandNothing,

these are Add-Ons, so there isn't any alert or report saved in savedsearch.conf.

then I don't understand your second question.

Usually Alerts and Reports are in Apps, not in Add-Ons.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @AllandNothing,

probably you didn't saved any alert or report in these apps but in different ones, for this reason you don't see savedsearches.conf in those apps.

Also because TA_Windows is also not visible and usually you don't use TA_nix.

Ciao.

Giuseppe

0 Karma

AllandNothing
Engager

Hello @gcusello, thanks for your answer,

in theory there arent't preconfigured searchs in these two apps? And in that case, why isn't present already wihout saving anything?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AllandNothing,

these are Add-Ons, so there isn't any alert or report saved in savedsearch.conf.

then I don't understand your second question.

Usually Alerts and Reports are in Apps, not in Add-Ons.

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @AllandNothing ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...