Reporting

Query about saved searches

MHibbin
Influencer

SplunkBase,

The following question is partially out of curiosity...

When a search string is saved as a report (e.g. a pie chart), where in the conf files is the information dictating the chart/report type used. I looked in the savedsearches.conf file, but there was no reference to the chart type, only to the search string, and some alert based options.

I have flicked through the rest of the App ($SPLUNK_HOME/etc/apps/<app_name/) directory but could not find a reference to the chart type, etc.

Apologies if I'm asking an obvious question, just haven't referenced this before.

Regards,

MHibbin

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

It's stored in personal viewstates.conf files under etc/users/, which are referenced by the vsid property in the savedsearches.conf file. However, these can (and should) be overridden by explicit setting if you use the search on an XML dashboard.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

It's stored in personal viewstates.conf files under etc/users/, which are referenced by the vsid property in the savedsearches.conf file. However, these can (and should) be overridden by explicit setting if you use the search on an XML dashboard.

MHibbin
Influencer

Ok thanks I see now.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...