Splunk Enterprise

How to recreate cpu memory usage searches?

TheBravoSierra
Path Finder

Because we are unable to use the monitoring console in Splunk Mobile, I would like to create our own monitoring console dashboard of sorts. Beginning with these searches, status, cpu usage, and memory usage of indexers and search heads. Does anyone have these searches available or know where I can locate them?

See attached screenshot for example.

Thanks

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Dashboards are in $SPLUNK_HOME/etc/apps/<app name>/default/data/ui/views.  Splunk tends to obfuscate their dashboard code so you'll likely have better luck viewing the panels by clicking on the "Open in Search" icon in the panel.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Why can you not use MC on mobile?

The searches you seek are all in $SPLUNK_HOME/etc/apps/splunk_monitoriing_console/default/savedsearches.conf.

---
If this reply helps you, Karma would be appreciated.

TheBravoSierra
Path Finder

I have access to view MC in Splunk Web but when I grant access for the same user to see it in mobile, they're unable to see it. Are you able to? Have you confirmed that is a supported functionality in Splunk Mobile? 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm unable to see the MC using Splunk Mobile, but that doesn't mean you can't copy the MC's searches into an app the mobile user can view.

---
If this reply helps you, Karma would be appreciated.
0 Karma

TheBravoSierra
Path Finder

In the location you specified above, I only see the saved searches. I don't see the searches for the dashboard panels. Would those be somewhere else?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Dashboards are in $SPLUNK_HOME/etc/apps/<app name>/default/data/ui/views.  Splunk tends to obfuscate their dashboard code so you'll likely have better luck viewing the panels by clicking on the "Open in Search" icon in the panel.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...