Splunk Search

How can I get the list of saved realtime searches and alerts as my disptach is filling up every now and then

New Member


I want to have list of all saved realtime searches and alerts as my dispatch is filling up every now and then. I want to contact the owner of the scheduled result so I want to have owners name also.


0 Karma


Hello @Amandeepsin,

please try the following :

| rest /services/saved/searches | table next_scheduled_time, eai:acl.owner

The next_scheduled_time info will let you know when the search will be scheduled next, and eai:acl.owner will let you know the user name. The rest command returns a lot of fields. Some of them may also help you.
More info about the rest command can be found in: https://docs.splunk.com/Documentation/Splunk/7.1.2/SearchReference/Rest

0 Karma
Get Updates on the Splunk Community!

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...