Reporting

how to filter a saved search

tsmithsplunk
Path Finder

(splunk 4.2) I have a saved search that returns too many categories to be visually clear in a chart. I would like to use the search for an entire dashboard, so I don't want to restrict it. I would like to just display the top 20 results in a chart so the categories will be readable. Can I filter the saved search using the simplified xml?

0 Karma

dturnbull_splun
Splunk Employee
Splunk Employee

On a dashboard with a form, you can use and . Otherwise you can use the savedsearch command to load a saved search, then pipe to head, for example.

0 Karma

tsmithsplunk
Path Finder

You may be assuming I know more than I do. Currently I'm using to access the saved search. I tried many variants but could not get them to work: | savedsearch mysearch; mysearch. Can I combine the and tags?

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...