Deployment Architecture

Splitting huge savedsearches.conf file into multiple files

xeyer10891
Engager

Hello team !

After unsuccessful research on the Internet / Splunk doc, I am turning to you for my question:
- Let's say I have 50 alerts in a single app, that are all stored in my file $SPLUNK_HOME$/etc/apps/<appname>/default/savedsearches.conf.

- For version control / code management, I want to split this single savedsearches.conf into multiples savedsearches.conf files so that developers can work with a folder directory looking like this:
| default |
| - | alerts |
| - | - | category_1_alerts |
| - | - | category_1_alerts | savedsearches.conf
| - | - | category_2_alerts |
| - | - | category_2_alerts | savedsearches.conf
...

- I tried without success on my Splunk instance. I don't know if it is possible, and if it this, I don't know if there are some statements to make in code (e.g. #include <filename>)

Have a nice day 🙂

PS :  In my version control / code management tool, I can always resort to concatenating all my files together when packaging Splunk code if I don't manage to find a better answer.

Labels (1)
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @xeyer10891,

no it isn't possible.

the only workaround is dividing alerts in different apps, but it isn't possible have a structured savedsearch.conf or local folder.

Ciao.

Giuseppe 

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @xeyer10891,

no it isn't possible.

the only workaround is dividing alerts in different apps, but it isn't possible have a structured savedsearch.conf or local folder.

Ciao.

Giuseppe 

xeyer10891
Engager

Thanks a lot!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @xeyer10891,

see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...