Splunk Enterprise

How to check particular saved search used in dashboards or alerts or reports?

Vani_26
Path Finder

Hi All,  

How can I search whether a particular saved search is being used in any dashboard or alerts or reports in Splunk.

Labels (1)
0 Karma

chaker
Contributor

You could set an alert around a search similar to this
index=_audit  sourcetype=audittrail (savedsearch_name="MySavedReport" OR savedsearch_name="YourSavedReport")

0 Karma

Vani_26
Path Finder

like if i want to see the paticular saved search is used in which dashbords i used below query i got the results:

|rest splunk_server="local"   "/servicesNS/-/-/data/ui/views"

|search "eai:data" ="My saved search name"

 

now i need the query for the same to see for  alerts or reports.

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...