I'm searching about how can I get the saved searches creation date, but I didn't see it in any documentation.
Is it possible to use rest command to see this info or any other command? I got only the updated field, but it's not what I need.
AFAIK, KO creation dates are not saved anywhere, with the exception of file-based KOs (lookup files, dashboards, datamodels) where the operating system tracks the file creation date. Splunk does not access the OS file creation date.
AFAIK, KO creation dates are not saved anywhere, with the exception of file-based KOs (lookup files, dashboards, datamodels) where the operating system tracks the file creation date. Splunk does not access the OS file creation date.