Other Usage

How to maintain savedsearches.conf in code repository?

leomax
New Member


Hello ,
I am trying to figure out how to enable users to maintain their saved searches , reports and alerts in version control.
Application teams login to Splunk UI and create their own reports , alerts etc.
Those get to be written to savedsearches.conf files , private or shared.

So application owners want their portion of the configuration be available to them to maintain in , say a Git repo.
We are using clustered searchhead deployment and also have a separate shc deployer system.
Thought about setting up a cron job to git clone /opt/splunk/etc/users/<user-id>/search/local/savedsearches.conf.
I am not sure how it may work, seemed clunky.

Is there any other way for teams (standard users)  to download , track and update their report, alert configuration without use of GUI ?

Thanks.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...