HI Team,
How can figure out reports/dashboard which owned by user, any Splunk query to find out, I tried from GUI as well but didn't work.
Let me know.
Thanks,
V
try :
| rest /servicesNS/PutUserNameHere/-/data/ui/views | table author title eai:acl.app | eval Type="Dashboard" | append [| rest /serviceNS/PutUserNameHere/-/saved/searches | table author title eai:acl.app | eval Type="SavedSearch/Report"] | rename author as Owner title as Name eai:.acl.app as AppName
Hi
Look at an example
index=_internal | rex "\/app\/(?<myApp>\w+)\/(?<myView>\w+)\"" | stats values(myView) AS myViews by user
The capture above is his result
If you want to add App which contain report or dashboard use this search code
index=_internal source=*access.log */app/* | rex "\/app\/(?<myApp>\w+)\/(?<myView>\w+)\"" | stats values(myApp) AS myApps , values(myView) AS myViews by user
Note that you can edit this search code as you want