I'm checking to see if property "actions" is not empty or property "alert.track" is "1" to check if it is an alert. But it looks like a new search query with some conditions added is also displayed in the alerts page.
So I would like to know if there is a combination of properties that I can use to distinguish an alert from a search object?
You need to use namespace wildcards to get all the searches (run as admin), I've added a filter to only load searches that have the email action enabled:
| rest /servicesNS/-/-/saved/searches search="action.email=1" | table title eai:acl.app eai:acl.owner disabled is_scheduled cron_schedule action.email*