Skip to main content
Detection to YAML Converter app icon

Detection to YAML Converter

Convert Splunk saved searches and ES detections into contentctl-compatible or custom YAML, individually or in bulk.Built by Sean McAuley
splunk product badge

Default Version 1.0.2

September 12, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.4

Rating
0
(0)

Log in to rate this app

Support
Not Supported

Detection YAML Converter is a small utility for moving saved searches out of the Splunk UI and into files. It converts Splunk saved searches and ES detections into YAML for contentctl or a custom detection-as-code repository. You can convert one detection or a batch, review the generated YAML, and download individual files or a ZIP. It reads saved-search configuration using the permissions of the logged-in user. It does not run, edit or delete searches, and Enterprise Security is not required. This is still a work in progress and generated files should be checked in your own repository. Splunk setups and contentctl implementations vary, so some fields may need adapting. A standalone savedsearches.conf conversion script is also included for cases where working from an exported conf file is easier.