Splunk Search

How to List objects of an application

somesoni2
Revered Legend

I have an apps which has views, saved searches, field extractions and macros. Is it possible to list all the objects of an app using splunk search??

Basically I want to know if Splunk stores the app's metadata in any of the indexes.
Thanks in advance.

Tags (2)
0 Karma
1 Solution

lguinn2
Legend

Splunk does not store knowledge objects in any index. Knowledge objects are contained in .conf files and .xml files that are stored in the directory hierarchy under $SPLUNK_HOME/etc

Shameless promotion: there is an app on Splunkbase called X-ray Splunk which collects information about the knowledge objects and presents it in a variety of dashboards. It doesn't seem to work yet on all OSes, but it is free.

View solution in original post

0 Karma

jaxjohnny2000
Builder

Take a look at this splunk base app: https://splunkbase.splunk.com/app/2871/

0 Karma

lguinn2
Legend

Splunk does not store knowledge objects in any index. Knowledge objects are contained in .conf files and .xml files that are stored in the directory hierarchy under $SPLUNK_HOME/etc

Shameless promotion: there is an app on Splunkbase called X-ray Splunk which collects information about the knowledge objects and presents it in a variety of dashboards. It doesn't seem to work yet on all OSes, but it is free.

0 Karma

somesoni2
Revered Legend

Thanks for you response roberts. I was looking for more of a search query to list that which can be displayed over a dashboard.

0 Karma

rroberts
Splunk Employee
Splunk Employee

Also, from the Manager->Apps menu you can click the "view objects" link and sort the objects under that app.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...