<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I find reports with email address. in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/How-can-I-find-reports-with-email-address/m-p/561317#M10855</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I have a clustered environment of Slunk setup. How can I find the all reports and alerts with email address. Actually I&amp;nbsp; need to correct the email domains again and I didn't found any correct way to check all reports with email address. Is there any search query and specific method to find out.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jul 2021 08:53:02 GMT</pubDate>
    <dc:creator>mbhardwaj1</dc:creator>
    <dc:date>2021-07-29T08:53:02Z</dc:date>
    <item>
      <title>How can I find reports with email address.</title>
      <link>https://community.splunk.com/t5/Reporting/How-can-I-find-reports-with-email-address/m-p/561317#M10855</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I have a clustered environment of Slunk setup. How can I find the all reports and alerts with email address. Actually I&amp;nbsp; need to correct the email domains again and I didn't found any correct way to check all reports with email address. Is there any search query and specific method to find out.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 08:53:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-can-I-find-reports-with-email-address/m-p/561317#M10855</guid>
      <dc:creator>mbhardwaj1</dc:creator>
      <dc:date>2021-07-29T08:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: How can I find reports with email address.</title>
      <link>https://community.splunk.com/t5/Reporting/How-can-I-find-reports-with-email-address/m-p/561330#M10896</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236918"&gt;@mbhardwaj1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this search?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest /servicesNS/-/-/saved/searches | where 'action.email'="1" | table title "action.email.to"&lt;/LI-CODE&gt;&lt;P&gt;OR&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest /servicesNS/-/-/saved/searches splunk_server=local | where 'action.email'="1" | table title "action.email.to"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 10:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-can-I-find-reports-with-email-address/m-p/561330#M10896</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-07-29T10:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: How can I find reports with email address.</title>
      <link>https://community.splunk.com/t5/Reporting/How-can-I-find-reports-with-email-address/m-p/561331#M10897</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236918"&gt;@mbhardwaj1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can issue this rest call to find them, action.email.to field having email address. Alternatively you can find savedsearches.conf file and grep/replace the domain that you wish to from backend.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest "/servicesNS/-/-/saved/searches" 
| table id search title action.email.to&lt;/LI-CODE&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and Accept solution if this reply helps!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 10:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-can-I-find-reports-with-email-address/m-p/561331#M10897</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-29T10:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: How can I find reports with email address.</title>
      <link>https://community.splunk.com/t5/Reporting/How-can-I-find-reports-with-email-address/m-p/561332#M10898</link>
      <description>&lt;P&gt;If you have multiple Search Heads (SH) and clustered you can push the changes to any one of the instance from SH deployer that will replicate across all cluster members. FYI, otherwise if they are not clustered you have to go modify on every instance manually.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 10:30:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-can-I-find-reports-with-email-address/m-p/561332#M10898</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-29T10:30:16Z</dc:date>
    </item>
  </channel>
</rss>

