Hi All,
I am new to Splunk and was looking for tutorials regarding Searching and Reporting on Splunk.
My question here is when we write Splunk queries and save those reports it gets saved to savedsearches.conf file. For my continuous deployment across different environments (dev,qa), we need a mechanism to import and run these queries on different Splunk instances.
Did some searching and found I could import/copy these savedsearches.conf to different instances and can see the reports/alerts created on host one is also coming up on host 2. Just want to know if this would be correct process to import all configuration across multiple Splunk servers?
Do any other processes need to be met for the above requirement? Please share the documentation, if so.
... View more