Reporting

Wanting to retrieve the recipient list associated with a scheduled search

Runals
Motivator

I'm trying to generate a report that shows scheduled searches and who is on the recipient list for emails. While I can go into the scheduler log and see what scheduled searches have fired I don't see an easy way to tie that back to who the email was sent to (other than manually going through each search).

Update
At least as far as 5.0.5 you can link the scheduler log with they python log via sid. Unfortunately the sid in the python log isn't populated for dashboards that have a scheduled delivery. At least as far as what I've been able to find.

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi Runals,

if I get it right, you can use the REST end point /services/saved/searches/ and check the fields action.email.bcc and action.email.cc. For example try this:

| rest /services/saved/searches/ | where 'action.email'!=0 | table title action.email.bcc action.email.cc

this will use all saved searches with enabled alerting and shows the name of the saved search and its recipients.

hope this helps ...

cheers, MuS

Runals
Motivator

That MuS - this gets me closer. The challenge is it isn't displaying information related to dashboards that have been scheduled for pdf delivery. Those show up as saved searches in the GUI (guessing in savedsearches.conf but haven't checked now that I think about it). It also appears to only return results for searches in the search app.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi @Runals, if you want to get all saved searches, use this REST search:

| rest /servicesNS/-/-/saved/searches/

Still not sure about the recipient part thought 😉

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...