Getting Data In

Is there a way to split the default savedsearches.conf from the local one?

hunterpj
Path Finder

I am using a search command to find the savedsearches.conf for an alert. I created a search which can list all of the parameters in the savedsearches.conf, however it merges both the default and local savedsearches.conf for that alert. the search I use is below:

| rest splunk_server=local /servicesNS/-/-/configs/conf-savedsearches search="eai:acl.app=INSERT_APP_NAME"
| search title="INSERT_ALERT_TITLE"
| rename eai:acl.app as app, eai:acl.perms.read as read, eai:acl.sharing as sharing
| fields - updated published id eai*
| fields title author splunk_server app read sharing *
| eval title="[".title."]"
| foreach * [eval title=if("<>"="author" OR "<>"="splunk_server" OR "<>"="app" OR "<>"="read"  OR "<>"="sharing" OR "<>"="title" OR '<>'="",title,mvappend(title,"<>"."="."\"".'<>'."\""))]
| fields title author splunk_server app read sharing
| search title=**

Is there any way for me to only see the local portion of the savedsearches.conf?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The only way to do that is using the CLI, either with btool or by directly examining the app's local/savedsearches.conf file.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The only way to do that is using the CLI, either with btool or by directly examining the app's local/savedsearches.conf file.

---
If this reply helps you, Karma would be appreciated.

MuS
Legend

Or like recommended in the other question https://answers.splunk.com/answers/668401/need-to-find-conf-files-on-a-splunk-interface-only.html#an... by using the Web Terminal App https://splunkbase.splunk.com/app/1607/ and run btool in there.

cheers, MuS

hunterpj
Path Finder

The Web Terminal kept crashing on my originally, but after I restarted the instance once it worked. Thank you!

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...