Splunk Cloud Platform

How to get savedsearch list in Splunk Cloud

skasagawa
Explorer

I know I can use the "rest" command as in the link below to get the list of savedsearches.

https://community.splunk.com/t5/Getting-Data-In/Is-there-any-way-to-list-all-the-saved-searches-in-S...

Since the "rest" command cannot be used in Splunk Cloud, I would like an SPL that can be listed without using that command.

It seems that the "rest" command can also be used if i contact Cloud Support, but I don't want to use that command as much as possible!

Best Regards.

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

What makes you think you can't use rest commands in SPL in Splunk Cloud?

Using the REST API SDK is different to using "| rest" commands in SPL

The "rest" commands only support read-only functions, but listing saved searches, as in that post, is possible.

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

What makes you think you can't use rest commands in SPL in Splunk Cloud?

Using the REST API SDK is different to using "| rest" commands in SPL

The "rest" commands only support read-only functions, but listing saved searches, as in that post, is possible.

 

0 Karma

skasagawa
Explorer

I was mistaken.
I was able to solve it with the query given in the link.
thank you for your help

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...