Splunk Search

Find Knowledge Objects created in last 24 hours

vamsigurram
Path Finder

 

I am looking for SPL, that can give me list of all the knowledge Objects, created in last 24 hours, in search app.

I looked at the below rest SPL, but i did not see creation time. 

| rest /servicesNS/-/search/directory

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Most KOs do not have a creation time in their REST output.  There is update_time, but it is rarely anything other than zero.

You can try looking in _audit and the access logs to creations, but I suspect you'll be less than successful.

You could do regular commits to a source management system and let it find the new objects for you, but that likely has its own limitations.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vamsigurram
Path Finder

Thanks richgalloway for the reply.

I will check _audit and see if that helps.

I will reply back with my findings.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...