Splunk Mission Control

Saved Filters in Mission Control

clumicao
New Member

Are we able to create a saved filter in Mission Control that can be shared across users? Just like in incident review in ES? 

Labels (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@clumicao 

I haven't worked on Mission Control before, but you can check this documentation – it might be helpful.

Apply filters and save filtered views for incidents

Triage incidents using incident review in Splunk Mission Control - Splunk Documentation

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

asimit
Path Finder

Hi @clumicao,

Currently, Mission Control does not have the same capability as Enterprise Security to create and share saved filters across users. In Mission Control, filters are saved locally to your browser and user profile, making them user-specific rather than shareable across a team.

There are a few workarounds you can use:

1. Document your most useful filters in a shared team document so others can manually recreate them
2. Use Mission Control's Export/Import feature to share filter configurations:
a. After creating a filter, click on the "Export" option in the filter panel
b. This will download a JSON configuration file
c. Share this file with team members
d. Other users can import this file using the "Import" option in their filter panel

Note that even with the import method, each user would need to import the filter individually, and any updates to the filter would require re-sharing and re-importing.

This has been a requested feature, and I recommend submitting it through the Splunk Ideas portal if it would be valuable for your team. The Splunk Mission Control team is regularly enhancing the product based on user feedback.

Please give 👍 for support 😁 happly splunking .... 😎

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...