Splunk Enterprise

Need help with preparing a list of Middleware reports on the Ent. + write an alert to be notified when they are changed.

SamHTexas
Builder

I need help with writing an SPL to list all the Middleware reports on the Splunk Ent. & An alert to email me when any report is changed please. Thank very much.

Labels (1)
Tags (1)
0 Karma

SinghK
Builder

All reports are saved searches 

|rest /servicesNS/-/-/saved/searches|table title, updated 

 

the spl query above will give you all the searches on your splunk instance and when they are updated. you will need to filter out your searches and setup and alert.

you can also add field "author" this way it will let you catch the person who changed it. 

inventsekar
Super Champion

Hi @SamHTexas .. we will need more details from your side..

 list all the Middleware reports  are they created by a same person / same app / same team? we got some rest api's that will list down all reports..

 

Once we created the SPL query to list down all middleware reports, its easy to create email alert. 

hope you got the idea, thanks. 

PS ... If any post helped you in any way, pls give a hi-five to the author with an upvote. if your issue got resolved, please accept the reply as solution.. thanks.
0 Karma

SamHTexas
Builder

Would you please share an SPL that would make a list of the only the middleware reports. Thanks a million

Tags (1)
0 Karma

SamHTexas
Builder

Thank u very much for your reply. Would you share a SPL I can use in GUI for all & one for 2 Teams that create the middleware reports. I really appreciate your help. Thx

Tags (1)
0 Karma

SinghK
Builder

Sam, 

 

this is the query

|rest /servicesNS/-/-/saved/searches|table title, updated, author. run that in search and you will get results.

SamHTexas
Builder

Thanks very much. Would this work on the Splunk Ent. as well as the ES? 

Tags (1)
0 Karma

SinghK
Builder

Yes.

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...