Reporting

Why can't we search within Searches, reports and alerts?

ddrillic
Ultra Champion

When we search within Searches, reports and alerts, we get the entire set of items.

What can it be? As we search for API in this example...

alt text

Tags (1)

burwell
SplunkTrust
SplunkTrust

Dear ddrillic: search for something like "nothere" which is unlikely to be in any of your search titles or the actual search. Does that match your searches, reports and alerts? I suggest this because API matched a lot of my searches too and not just the titles.

0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. If you have the string API in the subject or in the body of the search, it will match.

0 Karma

ddrillic
Ultra Champion

You see, the problem I have is that everything comes back, including items that don't match...

0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. What version of Splunk?

0 Karma

burwell
SplunkTrust
SplunkTrust

So a good test.. search for something like nothere which is unlikely to be in any of your search titles or the actual search. Does that match your searches, reports and alerts? I suggest this because API matched a lot of my searches too and not just the titles.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

HI @ddrillic,

Do you have any searches, reports or alerts in "AppName" app?

Can you please uncheck "show only objects created in this app context" checkbox? You might be found your desired savedsearches.

Thanks

0 Karma

ddrillic
Ultra Champion

No luck with that @kamlesh_vaghela.

I also tried searching for API* but everything comes back.

0 Karma

MuS
SplunkTrust
SplunkTrust

What does the messages tell you, you have 4 of them?

If you query the REST api directly can you get something back:

 | rest /servicesNS/-/-/saved/searches splunk_server=local | search title="api*"
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...