Dashboards & Visualizations

User Maintained Lists

andrewkenth
Communicator

Is there a way that I can have user maintain a list of values and then drive searches off said lists that does not involve importing a new sourcetype? Some of the searches used by the user are fairly complex and allowing the users to edit the normal and entire search is not advisable.

What are some recommendations for addressing this?

Thanks!

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could store your lists in lookups, and use the Sideview Utils Lookup Updater to maintain them.

If the number of values is small you may also use macros and give certain roles permission to edit their values.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...