Splunk Search

centralize search queries with links

at1ll3y
New Member

Hello community,

I'm currently building an application for a customer. Since the needs of the customer are steadily changing, I have to redefine the search queries from time to time. I'm using the same Queries in Reports, Dashboards and Alerts and have to make my changes in those three files places.
1. Is there any possibility to save a Search Query in on place (i.e. a String variable) and call it wherever it's needed (in Alerts, Reports and Dashboards)?
2. Is it furthermore possible to manage Dashboard tokens with this central saved Search query?

Thanks!

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

Hi @at1ll3y,
Have you tried saved searches

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...