Alerting

Saved search creation date

luislcruz
Engager

I'm searching about how can I get the saved searches creation date, but I didn't see it in any documentation.

Is it possible to use rest command to see this info or any other command? I got only the updated field, but it's not what I need. 

 

Labels (1)
Tags (1)
1 Solution

richgalloway
SplunkTrust
SplunkTrust

AFAIK, KO creation dates are not saved anywhere, with the exception of file-based KOs (lookup files, dashboards, datamodels) where the operating system tracks the file creation date.  Splunk does not access the OS file creation date.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

AFAIK, KO creation dates are not saved anywhere, with the exception of file-based KOs (lookup files, dashboards, datamodels) where the operating system tracks the file creation date.  Splunk does not access the OS file creation date.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...