Splunk saved search (and correlation search!) explorer

Image icon 2018-02-28_16-38-33.png272.35 KB
Plain text icon sse.txt6.94 KB
Plain text icon correlation_search_explorer.txt5.72 KB


As a Splunk administrator, have you ever needed to list out your saved searches in some way? Perhaps you need to know which searches might be accelerated, scheduled, or even real-time scheduled? Here's a quick dashboard to show this information.

The dashboard is attached as an txt file.

saved search explorer screenshot


Update: I have also created a Correlation Search explorer, which is now attached to this post as well. This new dashboard shows the data model and indexes associated with each correlation search.