I have asked to find a way to keep log who and when the saved searches or dashboards got edited. I have already read a lot of posts here but it seems none of them could help. I tried the following query which I found in another post but it seems only showing when the scheduled query runs instead showing when did the saved search get edited.
index=_internal sourcetype=splunkd_access
( method=POST OR method=DELETE )
( user!=sandy user!=splunk-system-user)
( uri_path=/servicesNS/* uri_path!="/user-prefs/" uri_path!="/servicesNS////jobs//control" uri_path!=/servicesNS//mobile_access )
| replace "/ui/views" with "/ui_views", "/props" with "*", "/distributed/peers*" with "/distributed_peers", "/server/serverclasses" with "/server_class" in uri_path
| where mvcount( split( uri_path , "/" ) ) > 6
| eval activity = case( method=="POST" AND like( uri_path , "%/acl" ) , "Permissions Update", method=="POST" AND NOT like( uri_path , "%/acl" ) , "Edited" , method="DELETE" , "Deleted" )
| rex field=uri_path "/servicesNS(/[^\/]+){3}/(?[^\/]+)/(?[^\/]+)"
| eval object_name = urldecode( object_name )
| table _time, user, object_name, object_type, activity