Right now I have scheduled searches that run at 2am for my app to repopulate csv lookup files. Is there any way for those scheduled searches to be deployed when I push my app out to our dev and production splunk servers?
create an app in the deployment server with a local folder containing a savedsearches.conf. Tie the app to the serverclass that you want to have the app and it will get there.
create an app in the deployment server with a local folder containing a savedsearches.conf. Tie the app to the serverclass that you want to have the app and it will get there.
Ah excellent. And it turns out the trick to these being saved in savedsearches.conf
is to have the search permissions set as app instead of private. Thanks