Splunk Cloud Platform

How to get savedsearch list in Splunk Cloud

skasagawa
Explorer

I know I can use the "rest" command as in the link below to get the list of savedsearches.

https://community.splunk.com/t5/Getting-Data-In/Is-there-any-way-to-list-all-the-saved-searches-in-S...

Since the "rest" command cannot be used in Splunk Cloud, I would like an SPL that can be listed without using that command.

It seems that the "rest" command can also be used if i contact Cloud Support, but I don't want to use that command as much as possible!

Best Regards.

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

What makes you think you can't use rest commands in SPL in Splunk Cloud?

Using the REST API SDK is different to using "| rest" commands in SPL

The "rest" commands only support read-only functions, but listing saved searches, as in that post, is possible.

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

What makes you think you can't use rest commands in SPL in Splunk Cloud?

Using the REST API SDK is different to using "| rest" commands in SPL

The "rest" commands only support read-only functions, but listing saved searches, as in that post, is possible.

 

0 Karma

skasagawa
Explorer

I was mistaken.
I was able to solve it with the query given in the link.
thank you for your help

0 Karma
Get Updates on the Splunk Community!

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...

New This Month - SLO Capabilities, APM Advanced Filtering & Usage Analytics Plus ...

More for SLO Management We’re continuing to expand the built-in SLO management experience in Splunk ...

Enterprise Security Content Update (ESCU) | New Releases

In June, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...