Reporting

Why can't we search within Searches, reports and alerts?

ddrillic
Ultra Champion

When we search within Searches, reports and alerts, we get the entire set of items.

What can it be? As we search for API in this example...

alt text

Tags (1)

burwell
SplunkTrust
SplunkTrust

Dear ddrillic: search for something like "nothere" which is unlikely to be in any of your search titles or the actual search. Does that match your searches, reports and alerts? I suggest this because API matched a lot of my searches too and not just the titles.

0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. If you have the string API in the subject or in the body of the search, it will match.

0 Karma

ddrillic
Ultra Champion

You see, the problem I have is that everything comes back, including items that don't match...

0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. What version of Splunk?

0 Karma

burwell
SplunkTrust
SplunkTrust

So a good test.. search for something like nothere which is unlikely to be in any of your search titles or the actual search. Does that match your searches, reports and alerts? I suggest this because API matched a lot of my searches too and not just the titles.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

HI @ddrillic,

Do you have any searches, reports or alerts in "AppName" app?

Can you please uncheck "show only objects created in this app context" checkbox? You might be found your desired savedsearches.

Thanks

0 Karma

ddrillic
Ultra Champion

No luck with that @kamlesh_vaghela.

I also tried searching for API* but everything comes back.

0 Karma

MuS
SplunkTrust
SplunkTrust

What does the messages tell you, you have 4 of them?

If you query the REST api directly can you get something back:

 | rest /servicesNS/-/-/saved/searches splunk_server=local | search title="api*"
0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...