Splunk saved search (and correlation search!) explorer

AttachmentSize
Image icon 2018-02-28_16-38-33.png272.35 KB

Categories:

As a Splunk administrator, have you ever needed to list out your saved searches in some way? Perhaps you need to know which searches might be accelerated, scheduled, or even real-time scheduled? Here's a quick dashboard to show this information.

The dashboard is available in this GitHub repo.

saved search explorer screenshot

 

Update: I have also created a Correlation Search explorer, which is now added to the github repo as well. This new dashboard shows the data model and indexes associated with each correlation search.