Hi,
I want to create an Alert which will trigger when any user created new alert or report in our environment. So could you please help me with suitable query for this.
| rest splunk_server=local servicesNS/-/-/saved/searches/
The updated field might be useful in this instance
Thank you for this query, but it will show all the reports and alerts. Actually i want to create an alert which will trigger if any user create one alert or report in splunk.
As I said, you can use the updated field to determine whether it has been updated / created recently - start by building a search to find the report updates / creations you are interested in