Reporting

how to disable the list of saved searches in savedsearches.conf?

pavanae
Builder

Just adding the below stanza wuld be sufficient to disable a saved search in default/savedsearches.conf

disabled = 1

How can I disable or enable a saved search in splunk from config side.

Is there any particullar location in savedsearches.conf I should be using that disabled stanza or I can use it anywhere under the saved search?

By default if I don't provide the disabled stanza what would be the default value that saved search has?

Labels (1)
0 Karma
1 Solution

manjunathmeti
Champion

"disabled" is an attribute not a stanza. To disable a saved search you need to add "disabled = 1" in th esaved search stanza in savedsearches.conf. By default disabled is 0. This setting actually used to to prevent a scheduled search from running. If your saved search is not scheduled then you don't need to add this attribute.

[saved_search_name]
disabled = 1

View solution in original post

0 Karma

manjunathmeti
Champion

"disabled" is an attribute not a stanza. To disable a saved search you need to add "disabled = 1" in th esaved search stanza in savedsearches.conf. By default disabled is 0. This setting actually used to to prevent a scheduled search from running. If your saved search is not scheduled then you don't need to add this attribute.

[saved_search_name]
disabled = 1
0 Karma

pavanae
Builder

Thank you for the clarification @manjunathmeti.

If I have a attribute setup in the beginning of the savedsearches.conf as follows

[default] 

disabled                = 1

Does that mean all the saved searches specified in that .conf files are disabled by default?

0 Karma
Get Updates on the Splunk Community!

Let’s Talk Terraform

If you’re beyond the first-weeks-of-a-startup stage, chances are your application’s architecture is pretty ...

Cloud Platform | Customer Change Announcement: Email Notification is Available For ...

The Notification Team is migrating our email service provider. As the rollout progresses, Splunk has enabled ...

Save the Date: GovSummit Returns Wednesday, December 11th!

Hey there, Splunk Community! Exciting news: Splunk’s GovSummit 2024 is returning to Washington, D.C. on ...