Splunk Cloud Platform

Scheduled searches and alerts not scheduled

python
Explorer

Hi,

 

How to query scheduled searches and alerts that is not scheduled?

Labels (1)
Tags (2)
0 Karma
1 Solution

kiran_panchavat
SplunkTrust
SplunkTrust

@python 

You can use this

is_scheduled=0 means Filters unscheduled searches.

| rest /services/saved/searches | where is_scheduled=0
To list all saved searches and alerts that are not scheduled
 
| rest /services/saved/searches
| search is_scheduled=0 alert_type=* disabled=0
| table title, qualifiedSearch, alert_type, is_scheduled, disabled
kiran_panchavat_1-1743777615296.png

 

| rest /services/saved/searches 
| where is_scheduled=0
| table title, description, search, eai:acl.owner, eai:acl.app

kiran_panchavat_0-1743777007342.png

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @python 

I see you have already accepted an answer to this, however I feel the answer isnt quite right, by using disabled=0 you are missing a bunch of searches which would otherwise be scheduled but have been disabled, so I feel you need to look for is_scheduled = 0 OR (disabled=1 AND is_scheduled = 1) as these are searches which would be scheduled if they werent disabled.

| rest /services/saved/searches
| search is_scheduled=0 OR (is_scheduled=1 AND disabled=1) alert_type=* 
| table disabled, is_scheduled, eai:acl.owner, eai:acl.app, title, qualifiedSearch, alert_type

livehybrid_0-1743803800276.png

🌟 Did this answer help you? If so, please consider:

  • Adding kudos to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

kiran_panchavat
SplunkTrust
SplunkTrust

@python 

You can use this

is_scheduled=0 means Filters unscheduled searches.

| rest /services/saved/searches | where is_scheduled=0
To list all saved searches and alerts that are not scheduled
 
| rest /services/saved/searches
| search is_scheduled=0 alert_type=* disabled=0
| table title, qualifiedSearch, alert_type, is_scheduled, disabled
kiran_panchavat_1-1743777615296.png

 

| rest /services/saved/searches 
| where is_scheduled=0
| table title, description, search, eai:acl.owner, eai:acl.app

kiran_panchavat_0-1743777007342.png

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...