Splunk Search

Where do i find the non-scheduled searches under backend.

Inayath_khan
Path Finder

iam able to see saved search under UI but not in savedsearches.conf.

Tags (1)
0 Karma

sanjeev543
Communicator

Hi @Inayath_khan are you talking about the scheduled search or just searched you saved as report/alert ?
Try searching in $SPLUNK_HOME/etc/users/<user Name>/<app>/local/savedsearches.conf

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@Inayath_khan

Use the below command to identify the path of your saved search configurations.

splunk cmd btool savedsearches list --debug

0 Karma

Inayath_khan
Path Finder

Thanks kamlesh but still i don't find my rule in any of savedsearches.conf.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...