September 12, 2026
Detection to YAML Converter
Convert Splunk saved searches and ES detections into contentctl-compatible or custom YAML, individually or in bulk.Built by Sean McAuleySplunk Enterprise, Splunk Cloud
Platform Version: 10.4
Log in to rate this app
Detection YAML Converter is a small utility for moving saved searches out of the Splunk UI and into files. It converts Splunk saved searches and ES detections into YAML for contentctl or a custom detection-as-code repository. You can convert one detection or a batch, review the generated YAML, and download individual files or a ZIP. It reads saved-search configuration using the permissions of the logged-in user. It does not run, edit or delete searches, and Enterprise Security is not required. This is still a work in progress and generated files should be checked in your own repository. Splunk setups and contentctl implementations vary, so some fields may need adapting. A standalone savedsearches.conf conversion script is also included for cases where working from an exported conf file is easier.
Log in to report this app listing.