Reporting

how to disable the list of saved searches in savedsearches.conf?

pavanae
Builder

Just adding the below stanza wuld be sufficient to disable a saved search in default/savedsearches.conf

disabled = 1

How can I disable or enable a saved search in splunk from config side.

Is there any particullar location in savedsearches.conf I should be using that disabled stanza or I can use it anywhere under the saved search?

By default if I don't provide the disabled stanza what would be the default value that saved search has?

Labels (1)
0 Karma
1 Solution

manjunathmeti
Champion

"disabled" is an attribute not a stanza. To disable a saved search you need to add "disabled = 1" in th esaved search stanza in savedsearches.conf. By default disabled is 0. This setting actually used to to prevent a scheduled search from running. If your saved search is not scheduled then you don't need to add this attribute.

[saved_search_name]
disabled = 1

View solution in original post

0 Karma

manjunathmeti
Champion

"disabled" is an attribute not a stanza. To disable a saved search you need to add "disabled = 1" in th esaved search stanza in savedsearches.conf. By default disabled is 0. This setting actually used to to prevent a scheduled search from running. If your saved search is not scheduled then you don't need to add this attribute.

[saved_search_name]
disabled = 1
0 Karma

pavanae
Builder

Thank you for the clarification @manjunathmeti.

If I have a attribute setup in the beginning of the savedsearches.conf as follows

[default] 

disabled                = 1

Does that mean all the saved searches specified in that .conf files are disabled by default?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...