Splunk Search

Where do i find the non-scheduled searches under backend.

Inayath_khan
Path Finder

iam able to see saved search under UI but not in savedsearches.conf.

Tags (1)
0 Karma

sanjeev543
Communicator

Hi @Inayath_khan are you talking about the scheduled search or just searched you saved as report/alert ?
Try searching in $SPLUNK_HOME/etc/users/<user Name>/<app>/local/savedsearches.conf

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@Inayath_khan

Use the below command to identify the path of your saved search configurations.

splunk cmd btool savedsearches list --debug

0 Karma

Inayath_khan
Path Finder

Thanks kamlesh but still i don't find my rule in any of savedsearches.conf.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...