How can I export alerts with names matching a specific phrase ( say "oscar"). And the report needs to include all the details of each alert settings, include search, schedule, etc.
Thanks
Try this
| rest splunk_server=local /servicesNS/-/-/saved/searches
| table title eai:acl.app search eai:acl.owner cron_schedule
| rename eai:acl.owner as owner
| search search=*oscar*
Try this
| rest splunk_server=local /servicesNS/-/-/saved/searches
| table title eai:acl.app search eai:acl.owner cron_schedule
| rename eai:acl.owner as owner
| search search=*oscar*
Thank you very much! How can I include schedule for each alert in the report? Thanks.
Thank you so much! How can I also include the time range? I tried "time_range", "earliest", "latest", but didn't work.
Thank you.
Need to strip off line 2 and look at all the fields available. I think you're probably looking for timespan. I've answered your original question. Can you please accept/upvote?
Please upvote and accept if this helped you.
I have edited my original answer to include the cron expression