Splunk saved search (and correlation search!) explorer


As a Splunk administrator, have you ever needed to list out your saved searches in some way? Perhaps you need to know which searches might be accelerated, scheduled, or even real-time scheduled? Here's a quick dashboard to show this information.

The dashboard is available in this GitHub repo.

saved search explorer screenshot


Update: I have also created a Correlation Search explorer, which is now attached to this post as well. This new dashboard shows the data model and indexes associated with each correlation search. This dashboard is not yet available in the repo linked above.