Splunk Search

how to clone a search window

elenzil
Path Finder

say i've got an interesting search going; it's yielding some pretty good values, but i think i might want to tweak it.

what i'd really like to do is just clone the whole splunk window, and modify the clone.

what i actually have done is written a little bash script to convert a search line into a URL - i copy my search term into the system clipboard, pipe it through my bash script, then paste the results into the URL bar in a new browser window.

it would be awesome if splunk had a button to do this for me, preserving the timerange from the original window.

1 Solution

Drainy
Champion

I can see the benefits of that, although in Chrome you can already right click and duplicate a tab. Though this won't preserve any results that Splunk might have already fetched it will preserve the search and time range.

Also you could always create it as a saved search and run that from the search window and just modify/clone it via the saved searches screen.

View solution in original post

Drainy
Champion

I can see the benefits of that, although in Chrome you can already right click and duplicate a tab. Though this won't preserve any results that Splunk might have already fetched it will preserve the search and time range.

Also you could always create it as a saved search and run that from the search window and just modify/clone it via the saved searches screen.

elenzil
Path Finder

thanks Drainy!

oh interesting - w/ splunk 4.3 it looks like the URL keeps up-to-date with the search you're working on, so just copying the URL is sufficient. that's great. previously that wasn't the case.

saving a search and editing it technically works, but practically has a couple issues: 1) it takes a lot of time to do. 2) it pollutes your saved-search space.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...