Splunk Search

How can I write a search that will list all the saved reports in my splunk environment?

Path Finder

I need to write search queries to list all the dashboards and reports saved in my splunk environment. I was able to list the dashboards by using

| rest /servicesNS/-/-/data/ui/views | search isDashboard=1 | search eai:acl.app=search |

but I am unable to write a query for the latter.

i thought | rest /servicesNS/-/-/data/ui/views | would at least list all the reports (among other views) and i would be able to filter the rest out. Unfortunately, this isn't even listing all the reports available to me.

I am a new user and any help is greatly appreciated.

Tags (2)
1 Solution

SplunkTrust
SplunkTrust

Hi saikatr,

how about using this REST endpoint:

| rest /services/saved/searches

cheers, MuS

View solution in original post

SplunkTrust
SplunkTrust

Hi saikatr,

how about using this REST endpoint:

| rest /services/saved/searches

cheers, MuS

View solution in original post

Path Finder

Thanks MuS,

This clearly sets me on the right path, This gave me a nice mix of reports and alerts:

| rest /services/saved/searches/ | search isvisible=1 | fields title isscheduled is_visible eai:acl.perms.write eai:acl.sharing

Would you by any chance be able to test this query and inform what might be the critical step to be able to list the reports and alerts separately?

0 Karma