Splunk Enterprise Security

Saved Search in Source Code

prateek1231
New Member

I am working on Splunk Enteprise Security. 

prateek1231_0-1737543082514.png

| savedsearch "Traffic  - Total Count" is working fine and giving me desired output in the search but when calling it in source code not showing any result.

{
    "type""ds.savedSearch",
    "options": {
        "query""'| savedsearch \"Traffic - Total Count\"'",
        "ref""Traffic - Total Count"
    },
    "meta": {
        "name""Traffic - Total Count"
    }
}

Do I need to do any configurations to get output on this dashboard???
Labels (2)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...