Splunk Mission Control

Saved Filters in Mission Control

clumicao
New Member

Are we able to create a saved filter in Mission Control that can be shared across users? Just like in incident review in ES? 

Labels (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@clumicao 

I haven't worked on Mission Control before, but you can check this documentation – it might be helpful.

Apply filters and save filtered views for incidents

Triage incidents using incident review in Splunk Mission Control - Splunk Documentation

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

asimit
Path Finder

Hi @clumicao,

Currently, Mission Control does not have the same capability as Enterprise Security to create and share saved filters across users. In Mission Control, filters are saved locally to your browser and user profile, making them user-specific rather than shareable across a team.

There are a few workarounds you can use:

1. Document your most useful filters in a shared team document so others can manually recreate them
2. Use Mission Control's Export/Import feature to share filter configurations:
a. After creating a filter, click on the "Export" option in the filter panel
b. This will download a JSON configuration file
c. Share this file with team members
d. Other users can import this file using the "Import" option in their filter panel

Note that even with the import method, each user would need to import the filter individually, and any updates to the filter would require re-sharing and re-importing.

This has been a requested feature, and I recommend submitting it through the Splunk Ideas portal if it would be valuable for your team. The Splunk Mission Control team is regularly enhancing the product based on user feedback.

Please give 👍 for support 😁 happly splunking .... 😎

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...