Splunk Search

How can I get the list of saved realtime searches and alerts as my disptach is filling up every now and then

Amandeepsin
New Member

Hi,

I want to have list of all saved realtime searches and alerts as my dispatch is filling up every now and then. I want to contact the owner of the scheduled result so I want to have owners name also.

Thanks,

0 Karma

poete
Builder

Hello @Amandeepsin,

please try the following :

| rest /services/saved/searches | table next_scheduled_time, eai:acl.owner

The next_scheduled_time info will let you know when the search will be scheduled next, and eai:acl.owner will let you know the user name. The rest command returns a lot of fields. Some of them may also help you.
More info about the rest command can be found in: https://docs.splunk.com/Documentation/Splunk/7.1.2/SearchReference/Rest

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...