I see the following in this app -
The search query is -
| rest /services/saved/searches splunk_server=local count=0
| search title="ESCU - *" | rename action.escu.search_type AS search_type
| eval search_type = upper(substr(search_type,1,1)) + lower(substr(search_type,2))
| stats count by search_type
What is it doing exactly? I guess it monitors itself ...
That search is providing how many different searches are available in ESCU app with different search types.
View solution in original post