Splunk Search

Where do i find the non-scheduled searches under backend.

Inayath_khan
Path Finder

iam able to see saved search under UI but not in savedsearches.conf.

Tags (1)
0 Karma

sanjeev543
Communicator

Hi @Inayath_khan are you talking about the scheduled search or just searched you saved as report/alert ?
Try searching in $SPLUNK_HOME/etc/users/<user Name>/<app>/local/savedsearches.conf

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@Inayath_khan

Use the below command to identify the path of your saved search configurations.

splunk cmd btool savedsearches list --debug

0 Karma

Inayath_khan
Path Finder

Thanks kamlesh but still i don't find my rule in any of savedsearches.conf.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...