Splunk Dev

How to show enabled or disabled number of saved searches w.r.t. hosts irrespective of time range?

jhantuSplunk
New Member

to show enabled or disabled number of saved searches w.r.t. hosts irrespective of time range in Splunk?

Tags (1)
0 Karma

jconger
Splunk Employee
Splunk Employee

This search may be what you want:

| rest /services/saved/searches | table title disabled splunk_server search

alt text

jhantuSplunk
New Member

I want do this by using index not rest

0 Karma

jconger
Splunk Employee
Splunk Employee

I'm not quite sure what you mean when you state "...using index...". Data about saved searches is not kept in an index. The search I posted above will give you information about saved searches though. I added a screenshot to the original answer to see an example.

0 Karma

vya9836
New Member

How do i need to get a report created on search head for the network/modular inputs which are created on a Heavy Forwarder using rest Api command.

0 Karma

vya9836
New Member

How do i need to get a report created on search head for the network/modular inputs which are created on a Heavy Forwarder using rest Api command.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...