...he XML where I'm trying to link to the report.
<searchString> | savedsearch "Digital_Match_and_Verify" idaFullName=$username$ </searchString>
<query>
| table i...
...also tried to achieve this by using panels based on reports. This also didn't work for me because my panels take inputs from the dashboard (for example, which hosts tosearch), but it seems like reports...
...s :
<query>| loadjob savedsearch="username:search:Domain_Controllers_Status_In_Splunk"</query>
</search>
It use work fine till last month, and now I don't see any data p...
I need to find the users that are using sourcetypes in their savedsearches (reports/dashboards). I have list of sourcetypes in csv file. SPL1:(this gives me source type list) | i...
I know this question has been asked a few times but none of the answers seem to work for me.
I have a savedsearch called usernameSearch and want to execute it synchronously using Splunk's REST A...
To reduce resource burden of scheduled searches (reports) and alerts off of the search heads, I have configured a default-mode.conf file to disable the pipeline:scheduler and created a separate job s...
...ersions listed in the web site and also have duplicate reports being sent when scheduled. I would assume that only version of each savedsearch would be active, as they use the same stanza names in the savedsearch...
...reated that savedsearch in the Splunk Searches, Reports, and Alerts interface. I have done back fills before but not since upgrading to 6.4. Is there something I am missing?
...ost_processing_search_terms
How does the append function work and how is it used correctly with reportsto perform various post-processing views of the data?
Follow-on points:
| loadjob o...
...he first 3 values and didn't find any problems in my searches, neither on my dashboards?
My question is when i should use Display View and How to customize new one on Splunk interface and link this v...