Hi,
I am looking for a query to extract respectively the list of alerts, reports and dashboards whose code cointains more than one join.
Thank you
Best regards
Marta
Just use the | rest command to list our saved searches (and dashboards) and search for the "join" word in the text of the associated search and find the matches.
https://docs.splunk.com/Documentation/Splunk/9.1.0/RESTREF/RESTprolog
Anyway, I'd look for even a single join.
thank you.
Marta
Just use the | rest command to list our saved searches (and dashboards) and search for the "join" word in the text of the associated search and find the matches.
https://docs.splunk.com/Documentation/Splunk/9.1.0/RESTREF/RESTprolog
Anyway, I'd look for even a single join.