Splunk Enterprise

How to check particular saved search used in dashboards or alerts or reports?

Vani_26
Path Finder

Hi All,  

How can I search whether a particular saved search is being used in any dashboard or alerts or reports in Splunk.

Labels (1)
0 Karma

chaker
Contributor

You could set an alert around a search similar to this
index=_audit  sourcetype=audittrail (savedsearch_name="MySavedReport" OR savedsearch_name="YourSavedReport")

0 Karma

Vani_26
Path Finder

like if i want to see the paticular saved search is used in which dashbords i used below query i got the results:

|rest splunk_server="local"   "/servicesNS/-/-/data/ui/views"

|search "eai:data" ="My saved search name"

 

now i need the query for the same to see for  alerts or reports.

0 Karma
Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...