You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Sep 2, 2025. It is now read-only.
:description: Collaborate with team members by sharing Log Observer or Log Observer Connect queries. Saved queries include filters, aggregations, and search-time rules.
8
+
:description: Collaborate with team members by sharing Log Observer Connect queries. Saved queries include filters, aggregations, and search-time rules.
9
9
10
10
11
11
After you create useful queries in Log Observer Connect, you can save them and share them with team members. You can only save or share queries on the :guilabel:`Splunk Observability Cloud data` index. A saved query is made up of a filter and any aggregations or search-time rules you applied during the search. You can only save a query if you have created a filter.
12
12
13
-
To learn how to create filters, see :ref:`logs-keyword`.
14
-
Log Observer Connect has no default aggregation. Log Observer defaults to :guilabel:`All (*)`` logs grouped by :guilabel:`Severity`. To learn how to create a unique aggregation, see :ref:`logs-aggregations`.
13
+
To learn how to create filters, see :ref:`logs-keyword`. Log Observer Connect has no default aggregation. To learn how to create a unique aggregation, see :ref:`logs-aggregations`.
15
14
16
15
.. note::
17
16
All organizations have access to pre-defined queries for Kubernetes and Cassandra. These queries appear at the beginning of the list of saved queries and are a part of content packs. Content packs include pre-defined saved queries as well as log processing rules. Splunk Observability Cloud includes content packs for Kubernetes System Events and Cassandra.
@@ -20,10 +19,10 @@ You can also download the results of a query as a CSV or JSON file. See :ref:`ex
0 commit comments