Splunk Search

Organizing "Searches and Reports" and "Views"

davidc
Engager

What's the best way to organize "Searches and Reports" and "Views"? I'm trying to figure out some type of structure before it's to late. Currently we have 20 - 30 of each and it's a pain selecting "Searches and Reports" and seeing ALL searches ditto for "Views".

I would like to create a service subfolder and add searches and reports that are associated to that service.

Is this possible? I'm running Splunk 4.1.6

Tags (1)

Paolo_Prigione
Builder

Yes it does. You can just nest the <collection> tags one into each other.

<collection label="Status">
    <collection label="Search activity">
      <view name="search_status" />
      <view name="search_detail_activity" />
      <view name="search_user_activity" />
      <view name="search_ui_activity" />
    </collection>
    <collection label="Index activity">
      <view name="index_status" />
....

stefanlasiewski
Contributor
0 Karma

davidc
Engager

NM. I figured it out.

Does Splunk 4.1.6 support multi-level nav menu?

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...