Splunk Search

Where do i find the non-scheduled searches under backend.

Inayath_khan
Path Finder

iam able to see saved search under UI but not in savedsearches.conf.

Tags (1)
0 Karma

sanjeev543
Communicator

Hi @Inayath_khan are you talking about the scheduled search or just searched you saved as report/alert ?
Try searching in $SPLUNK_HOME/etc/users/<user Name>/<app>/local/savedsearches.conf

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@Inayath_khan

Use the below command to identify the path of your saved search configurations.

splunk cmd btool savedsearches list --debug

0 Karma

Inayath_khan
Path Finder

Thanks kamlesh but still i don't find my rule in any of savedsearches.conf.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...