Saved searches
A saved search stores the whole state of an events list under a name, so you can come back to it in one click. This page covers saving, loading and deleting them, and how they differ from filters.
What a saved search holds
A saved search is a snapshot of the page: the list you are on, the layout (List or Map), the toolbar filters, Show, Label, Tag, the quick range or time range, the scope and the Advanced search conditions. Loading it puts all of those back exactly as they were.
Saved searches belong to your account and to one list: the picker on the es-python list shows es-python searches only. They sit in the Advanced search panel, under the Saved search picker.
Save a search
Set the filters you want, open Advanced search, and click Save beside the Saved search picker. Type a name (up to 80 characters) in the box that appears and click Save search, or press Enter. Escape or Cancel closes the box without saving.
Saving under a name you already use replaces that search. To update a search, load it, change the filters, click Save (the box starts with its current name) and save again.
Load a search
Pick a name in the Saved search picker. Every filter on the page is cleared first and then set from the search, so nothing from before stays behind. The page address changes to match, so you can bookmark or share the result like any filtered view.
Choosing none only deselects the picker; it does not change the filters. After Reset, the picker goes back to none.
A search saved with a relative time (a quick range such as 24h, or 2h ago in From) is relative to when you load it, not when you saved it.
Delete a search
Pick the search, click Delete and confirm. This removes the saved search only; it does not change any events or filters.
Saved searches and filters
A saved search and a filter are different things. A saved search is a page state you come back to when you choose; it changes nothing until you load it. A filter on the Filters page is a standing rule applied to every query from then on, shown by the N filters active badge next to Reset.
Use a saved search for a question you ask often ("critical events on the web servers this week"). Use a filter, or Block from the row menu, for events you never want to see.