Hello everybody,
is there a way to plan searches by editing a configuration file? Usually I plan searches through splunk web, setting start time, ending time, alerts and etc...now I want to do the same thing writing the searches into a config file. It is possible?
Yes, It's savedsearches.conf
Ok, but I want to do this allowing an application(written on my own) to edit a config file. Is this file "savedsearches.conf"?
Ok, but I want to do this allowing an application(written on my own) to edit a config file. Is this file "savedsearches.conf"?
Sounds like what you want is a saved search? http://docs.splunk.com/Documentation/Splunk/5.0.2/Tutorial/Saveasearch