SavedSearches
Query the saved search definitions in Splunk.
Columns
| Name | Type | Description |
| Name [KEY] | String | The name of the saved search. |
| Id | String | The REST resource link for the saved search. |
| UpdatedAt | Datetime | Datetime of the last update of the saved search. |
| Author | String | The Splunk user that created the saved search. |
| App | String | The Splunk app where the saved search is shared. |
| CanList | Boolean | Indicates whether the saved search can be listed by the user. |
| CanWrite | Boolean | Indicates whether the saved search can be modified by the user. |
| Modifiable | Boolean | Indicates whether the saved search can be modified. |
| Owner | String | The Splunk user that owns the saved search. |
| ReadPermissions | String | Permissions to read this saved search. |
| WritePermissions | String | Permissions to write to this saved search. |
| Removable | Boolean | Indicates whether the saved search can be removed. |
| Sharing | String | The saved search sharing type. |
| Search | String | The search query that the saved search runs. |
| Description | String | Human-readable description of the saved search. |
| Disabled | Boolean | Indicates whether the saved search is disabled. |
| CronSchedule | String | The cron schedule used to run this saved search. |
| IsScheduled | Boolean | Indicates whether this saved search is run on a schedule. |
| IsVisible | Boolean | Indicates whether this saved search appears in the visible saved search list. |
| RealtimeSchedule | Boolean | Controls how the scheduler computes the next execution time of the saved search. |
| RunOnStartup | Boolean | Indicates whether this saved search runs on startup. |
| RunNTimes | Integer | Runs this saved search exactly the specified number of times. |
| SchedulePriority | String | The scheduling priority of this saved search. |
| ScheduleWindow | String | Time window, in minutes, during which the search has lower priority. |
| MaxConcurrent | Integer | The maximum number of concurrent instances of this search the scheduler is allowed to run. |
| NextScheduledTime | Datetime | Time when the scheduler runs this search again. |
| QualifiedSearch | String | The exact search string that the scheduler runs. |
| AllowSkew | String | Allows the search scheduler to distribute scheduled searches more evenly over their specified periods. |
| DispatchAs | String | Controls which user a dispatched search runs as. Set to owner or user. |
| DisplayView | String | The default UI view name in which to load the results. |
| Vsid | String | The viewstate id associated with the UI view listed in DisplayView. |
| AlertDigestMode | Boolean | Indicates whether alert actions are applied to the entire result set or to each individual result. |
| AlertExpires | String | The period of time to show the alert in the dashboard. |
| AlertManagedBy | String | The feature or component that created the alert. |
| AlertSeverity | Integer | The alert severity level. |
| AlertSuppress | Boolean | Indicates whether alert suppression is enabled for this scheduled search. |
| AlertSuppressFields | String | List of fields to use when suppressing per-result alerts. |
| AlertSuppressGroupName | String | Defines an alert suppression group for a set of alerts running over similar datasets. |
| AlertSuppressPeriod | String | The suppression period. Only valid if alert suppression is enabled. |
| AlertTrack | String | Specifies whether to track the actions triggered by this scheduled search. |
| AlertComparator | String | The comparator used with AlertThreshold to trigger alert actions. |
| AlertCondition | String | A conditional search that is evaluated against the results of the saved search. |
| AlertThreshold | String | The value to compare before triggering the alert actions. |
| AlertType | String | What to base the alert on. Overridden by AlertCondition if it is specified. |
| AutoSummarize | Boolean | Specifies whether the search scheduler should ensure the data for this search is automatically summarized. |
| AutoSummarizeCommand | String | A search template used to construct the auto-summarization for the search. |
| AutoSummarizeCronSchedule | String | Cron schedule used to probe or generate the summaries for this search. |
| AutoSummarizeMaxConcurrent | Integer | The maximum number of concurrent instances of this auto-summarizing search the scheduler may run. |
| AutoSummarizeMaxDisabledBuckets | Integer | The maximum number of buckets with suspended summarization before summarization is stopped. |
| AutoSummarizeMaxSummaryRatio | Double | The maximum ratio of summary size to bucket size before summarization is deemed unhelpful. |
| AutoSummarizeMaxSummarySize | Integer | The minimum summary size, in bytes, before testing whether the summarization is helpful. |
| AutoSummarizeMaxTime | Integer | The maximum time, in seconds, that the auto-summarization search is allowed to run. |
| AutoSummarizeSuspendPeriod | String | The amount of time to suspend summarization of the search if the summarization is deemed unhelpful. |
| AutoSummarizeTimespan | String | Comma-delimited list of time ranges that each summarized chunk should span. |
| ActionEmail | Boolean | Indicates the state of the email action. |
| ActionEmailTo | String | List of recipient email addresses. |
| ActionEmailFrom | String | Email address from which the email action originates. |
| ActionEmailCc | String | CC email address to use if the email action is enabled. |
| ActionEmailBcc | String | BCC email address to use if the email action is enabled. |
| ActionEmailSubject | String | The email subject for the email action. |
| ActionEmailFormat | String | The format of text in the email. Valid values: plain, html, raw, csv. |
| ActionEmailSendResults | Boolean | Indicates whether to attach the search results in the email. |
| ActionEmailSendPdf | Boolean | Indicates whether to create and send the results as a PDF. |
| ActionEmailInline | Boolean | Indicates whether the search results are contained in the body of the email. |
| ActionEmailMailServer | String | The address of the MTA server used to send the emails. |
| ActionEmailMaxResults | Integer | The global maximum number of search results to send when the email action is enabled. |
| ActionEmailMaxTime | String | The maximum amount of time the execution of an email action takes before the action is aborted. |
| ActionEmailUseSsl | Boolean | Indicates whether to use SSL when communicating with the SMTP server. |
| ActionEmailUseTls | Boolean | Indicates whether to use TLS when communicating with the SMTP server. |
| ActionRss | Boolean | The state of the RSS action. |
| ActionScript | Boolean | The state of the script action. |
| ActionPopulateLookup | Boolean | The state of the populate lookup action. |
| ActionSummaryIndex | Boolean | Indicates whether the summary index action is enabled for this search. |
| ActionSummaryIndexInline | Boolean | Indicates whether to execute the summary indexing action as part of the scheduled search. |
| DispatchEarliestTime | String | A time string that specifies the earliest time for this search. |
| DispatchLatestTime | String | A time string that specifies the latest time for this search. |
| DispatchIndexEarliest | String | The earliest index time for this search. |
| DispatchIndexLatest | String | The latest index time for this search. |
| DispatchTtl | String | The time to live, in seconds, for the artifacts of the scheduled search if no actions are triggered. |
| DispatchMaxCount | Integer | The maximum number of results before finalizing the search. |
| DispatchMaxTime | Integer | The maximum amount of time, in seconds, before finalizing the search. |
| DispatchBuckets | Integer | The maximum number of timeline buckets. |
| DispatchLookups | Boolean | Indicates whether lookups are enabled for this search. |
| DispatchReduceFreq | Integer | How frequently the MapReduce reduce phase runs on accumulated map values. |
| DispatchRtBackfill | Boolean | Indicates whether to do real-time window backfilling for scheduled real-time searches. |
| DispatchSampleRatio | String | The integer value used to calculate the sample ratio. |
| DispatchTimeFormat | String | Time format string that defines the format for specifying the earliest and latest time. |
| DispatchSpawnProcess | Boolean | Indicates whether a new search process is spawned when this saved search is executed. |
| DispatchAllowPartialResults | Boolean | Indicates whether the search job can proceed with partial results if a search peer fails. |
| DispatchAutoCancel | String | The amount of inactive time, in seconds, after which the search job is automatically canceled. |
| DispatchAutoPause | String | The amount of inactive time, in seconds, after which the search job is automatically paused. |
| RestartOnSearchpeerAdd | Boolean | Indicates whether to restart a real-time search when a search peer becomes available. |
| RequestUiDispatchApp | String | The app this search should be dispatched in, used by Splunk Web. |
| RequestUiDispatchView | String | The view this search should be displayed in, used by Splunk Web. |
| DeferScheduledSearchableIdxc | Boolean | Indicates whether to defer a continuous saved search during a searchable rolling restart of an indexer cluster. |
| DurableTrackTimeType | String | Indicates whether the scheduled search is durable and how it tracks events. |
| DurableLagTime | String | The search time delay, in seconds, used to catch events that are ingested or indexed late. |
| DurableBackfillType | String | How the Splunk software backfills the lost search results of failed scheduled search jobs. |
| DurableMaxBackfillIntervals | Integer | The maximum number of cron intervals the Splunk software can attempt to backfill for this search. |
| Published | Datetime | Datetime when the saved search entry was published. |