Reporting

Can i see the full SPL of a saved search for debugging with tokens and time filled in automatically

robertlynch2020
Motivator

I have the following in my dashboard

| savedsearch HOME_BREAKDOWN_BASE TOKEN_LOOKUPHOST_SOURCETYPE_TIME="HOME_HOST_SOURCETYPE_TIME_LIVE.csv" TOKEN_INDEX="mlc_live" TOKEN_EMAIL="HOME_EMAIL_LIVE.csv"

But i want to see the full SPL with out having to open the sacedsearch and full in all the host tokens and time, is there a quick way to do this?

Thanks Rob

493669
Super Champion

Are you looking for something like this-

| rest /services/saved/searches | dedup search | table title search
0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...