Splunk Search

centralize search queries with links

at1ll3y
New Member

Hello community,

I'm currently building an application for a customer. Since the needs of the customer are steadily changing, I have to redefine the search queries from time to time. I'm using the same Queries in Reports, Dashboards and Alerts and have to make my changes in those three files places.
1. Is there any possibility to save a Search Query in on place (i.e. a String variable) and call it wherever it's needed (in Alerts, Reports and Dashboards)?
2. Is it furthermore possible to manage Dashboard tokens with this central saved Search query?

Thanks!

0 Karma

renjith_nair
Legend

Hi @at1ll3y,
Have you tried saved searches

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...