Reporting

Query about saved searches

MHibbin
Influencer

SplunkBase,

The following question is partially out of curiosity...

When a search string is saved as a report (e.g. a pie chart), where in the conf files is the information dictating the chart/report type used. I looked in the savedsearches.conf file, but there was no reference to the chart type, only to the search string, and some alert based options.

I have flicked through the rest of the App ($SPLUNK_HOME/etc/apps/<app_name/) directory but could not find a reference to the chart type, etc.

Apologies if I'm asking an obvious question, just haven't referenced this before.

Regards,

MHibbin

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

It's stored in personal viewstates.conf files under etc/users/, which are referenced by the vsid property in the savedsearches.conf file. However, these can (and should) be overridden by explicit setting if you use the search on an XML dashboard.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

It's stored in personal viewstates.conf files under etc/users/, which are referenced by the vsid property in the savedsearches.conf file. However, these can (and should) be overridden by explicit setting if you use the search on an XML dashboard.

MHibbin
Influencer

Ok thanks I see now.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...