Reporting

How can I find reports with email address.

mbhardwaj1
Engager

Hi ,

I have a clustered environment of Slunk setup. How can I find the all reports and alerts with email address. Actually I  need to correct the email domains again and I didn't found any correct way to check all reports with email address. Is there any search query and specific method to find out.

0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

@mbhardwaj1 

Can you please try this search?

| rest /servicesNS/-/-/saved/searches | where 'action.email'="1" | table title "action.email.to"

OR

| rest /servicesNS/-/-/saved/searches splunk_server=local | where 'action.email'="1" | table title "action.email.to"

 

View solution in original post

venkatasri
SplunkTrust
SplunkTrust

Hi @mbhardwaj1 

You can issue this rest call to find them, action.email.to field having email address. Alternatively you can find savedsearches.conf file and grep/replace the domain that you wish to from backend.

| rest "/servicesNS/-/-/saved/searches" 
| table id search title action.email.to

---

An upvote would be appreciated and Accept solution if this reply helps!

0 Karma

venkatasri
SplunkTrust
SplunkTrust

If you have multiple Search Heads (SH) and clustered you can push the changes to any one of the instance from SH deployer that will replicate across all cluster members. FYI, otherwise if they are not clustered you have to go modify on every instance manually.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@mbhardwaj1 

Can you please try this search?

| rest /servicesNS/-/-/saved/searches | where 'action.email'="1" | table title "action.email.to"

OR

| rest /servicesNS/-/-/saved/searches splunk_server=local | where 'action.email'="1" | table title "action.email.to"

 

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...