<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Saved search creation date in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Saved-search-creation-date/m-p/561029#M10690</link>
    <description>&lt;P&gt;I'm searching about how can I get the saved searches creation date, but I didn't see it in any documentation.&lt;/P&gt;&lt;P&gt;Is it possible to use rest command to see this info or any other command? I got only the updated field, but it's not what I need.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jul 2021 14:02:52 GMT</pubDate>
    <dc:creator>luislcruz</dc:creator>
    <dc:date>2021-07-27T14:02:52Z</dc:date>
    <item>
      <title>Saved search creation date</title>
      <link>https://community.splunk.com/t5/Alerting/Saved-search-creation-date/m-p/561029#M10690</link>
      <description>&lt;P&gt;I'm searching about how can I get the saved searches creation date, but I didn't see it in any documentation.&lt;/P&gt;&lt;P&gt;Is it possible to use rest command to see this info or any other command? I got only the updated field, but it's not what I need.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 14:02:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Saved-search-creation-date/m-p/561029#M10690</guid>
      <dc:creator>luislcruz</dc:creator>
      <dc:date>2021-07-27T14:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Saved search creation date</title>
      <link>https://community.splunk.com/t5/Alerting/Saved-search-creation-date/m-p/561057#M10691</link>
      <description>&lt;P&gt;AFAIK, KO creation dates are not saved anywhere, with the exception of file-based KOs (lookup files, dashboards, datamodels) where the operating system tracks the file creation date.&amp;nbsp; Splunk does not access the OS file creation date.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 16:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Saved-search-creation-date/m-p/561057#M10691</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-07-27T16:59:43Z</dc:date>
    </item>
  </channel>
</rss>

