I have deployed ChargeBack on the Splunk Cloud and the sc_admin is not allowed to have the dispatch_rest_to_indexers capability.
My question is how can I replace the | REST calls on their searches to achieve the same results?
the main initial search is
| rest /services/data/indexes splunk_server=*
thanks,
-CC
That app and others that use REST calls do so because there is no other way to get the necessary data.
You should be able to get what you need from the search head. The REST command in your question works find on a SH because on Splunk Cloud the SH has the same list of indexes as do the indexers. Just ignore the warnings about dispatch_rest_to_indexers.