You get the list of alerts like this:
|rest/servicesNS/admin/search/saved/searches | search disabled=1 | table title | outputlookup mylookup
You run this as a saved search every 24-hours and use outputlookup
to save the results. You also save a similar search to run just before the first one that uses inputlookup
and compares the 2 looking for new entries and ignoring old entries like this:
|rest/servicesNS/admin/search/saved/searches | search disabled=1 | table title | eval type="new" | append [|inputlookup mylookup | eval type="old]" | stats values(type) AS types BY title | where types!="old"
You get the list of alerts like this:
|rest/servicesNS/admin/search/saved/searches | search disabled=1 | table title | outputlookup mylookup
You run this as a saved search every 24-hours and use outputlookup
to save the results. You also save a similar search to run just before the first one that uses inputlookup
and compares the 2 looking for new entries and ignoring old entries like this:
|rest/servicesNS/admin/search/saved/searches | search disabled=1 | table title | eval type="new" | append [|inputlookup mylookup | eval type="old]" | stats values(type) AS types BY title | where types!="old"
Hi Woodcock
Can we merge these two search
Possibly but I think it would be highly inadvisable.