Splunk Dev

How to show enabled or disabled number of saved searches w.r.t. hosts irrespective of time range?

jhantuSplunk
New Member

to show enabled or disabled number of saved searches w.r.t. hosts irrespective of time range in Splunk?

Tags (1)
0 Karma

jconger
Splunk Employee
Splunk Employee

This search may be what you want:

| rest /services/saved/searches | table title disabled splunk_server search

alt text

jhantuSplunk
New Member

I want do this by using index not rest

0 Karma

jconger
Splunk Employee
Splunk Employee

I'm not quite sure what you mean when you state "...using index...". Data about saved searches is not kept in an index. The search I posted above will give you information about saved searches though. I added a screenshot to the original answer to see an example.

0 Karma

vya9836
New Member

How do i need to get a report created on search head for the network/modular inputs which are created on a Heavy Forwarder using rest Api command.

0 Karma

vya9836
New Member

How do i need to get a report created on search head for the network/modular inputs which are created on a Heavy Forwarder using rest Api command.

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...