Splunk Search

Find Knowledge Objects created in last 24 hours

vamsigurram
Path Finder

 

I am looking for SPL, that can give me list of all the knowledge Objects, created in last 24 hours, in search app.

I looked at the below rest SPL, but i did not see creation time. 

| rest /servicesNS/-/search/directory

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Most KOs do not have a creation time in their REST output.  There is update_time, but it is rarely anything other than zero.

You can try looking in _audit and the access logs to creations, but I suspect you'll be less than successful.

You could do regular commits to a source management system and let it find the new objects for you, but that likely has its own limitations.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vamsigurram
Path Finder

Thanks richgalloway for the reply.

I will check _audit and see if that helps.

I will reply back with my findings.

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...