I need to write search queries to list all the dashboards and reports saved in my splunk environment. I was able to list the dashboards by using
| rest /servicesNS/-/-/data/ui/views | search isDashboard=1 | search eai:acl.app=search |
but I am unable to write a query for the latter.
i thought | rest /servicesNS/-/-/data/ui/views | would at least list all the reports (among other views) and i would be able to filter the rest out. Unfortunately, this isn't even listing all the reports available to me.
I am a new user and any help is greatly appreciated.
This clearly sets me on the right path, This gave me a nice mix of reports and alerts:
| rest /services/saved/searches/ | search isvisible=1 | fields title isscheduled is_visible eai:acl.perms.write eai:acl.sharing
Would you by any chance be able to test this query and inform what might be the critical step to be able to list the reports and alerts separately?