Getting Data In

Using REST API to review tag=suppress, updated field not updated with last change date/time

carlkennedy_tsy
Engager

Using this SPL:

| rest servicesNS/-/-/search/tags/suppress splunk_server=local

I get a list of all of the searches that result in tag=suppress. It seems that the outputted field labeled "updated" only contains when the original tag was created and does not reflect when each search was updated. Is there a way to see when each search was updated for a particular tag?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...