Splunk Search

Where do i find the non-scheduled searches under backend.

Inayath_khan
Path Finder

iam able to see saved search under UI but not in savedsearches.conf.

Tags (1)
0 Karma

sanjeev543
Communicator

Hi @Inayath_khan are you talking about the scheduled search or just searched you saved as report/alert ?
Try searching in $SPLUNK_HOME/etc/users/<user Name>/<app>/local/savedsearches.conf

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@Inayath_khan

Use the below command to identify the path of your saved search configurations.

splunk cmd btool savedsearches list --debug

0 Karma

Inayath_khan
Path Finder

Thanks kamlesh but still i don't find my rule in any of savedsearches.conf.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...