Splunk Search

What is the difference between views and searches in uri after an app name?

JuhiSaxena
Explorer

In an uri of any saved search at some places there is '/views/' and '/searches/' after an app name. I want to know the difference between views and searches in uri. What do they signify? Is this related to Dashboards and alerts?

Tags (4)
0 Karma

somesoni2
Revered Legend

I believe they are the URI of the management pages for User Interfaces (one with /views/, from Settings->User Interfaces->Views) and Saved searches (one with /searches/, from Settings-> Searches, Reports, and Alerts). We can say for sure if you post some sample values for the URI (mask any sensitive information).

0 Karma

JuhiSaxena
Explorer

Thank you, this clears lot of things to me.
As an example lets suppose below is the uri and I want to know whether this is an Alert or is a dashboard.

en-US/splunkd/__raw/servicesNS/nobody/search/saved/searches/Error%20Alerts%20for%20%20XYZ%20Application

Thanks

0 Karma

somesoni2
Revered Legend

Anything with URI of type `search/saved/searches´ is a saved search and could be a report or alert.

0 Karma

JuhiSaxena
Explorer

okay and anything with uri of type 'data/ui/views' could be a dashboard, like :

/en-US/splunkd/__raw/servicesNS/juhi/someservice/data/ui/views/usage_by_host

0 Karma

somesoni2
Revered Legend

Thats correct.

0 Karma

JuhiSaxena
Explorer

Thank you so much 🙂

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...