- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sanz
Explorer
08-02-2022
05:45 AM
Hi I'm new to Splunk and what to create a search that shows what savedsearches where used in a dashboard?
This is how far I got:
| rest /servicesNS/-/-/data/ui/views splunk_server=local
| search title="test_dashboard"
| rename eai:acl.app AS app, eai:data AS data
| fields title app author data
I have no clue how to go from this data to an actual list of savedsearches used in this dashboard.
Is there anyone who can put me on a good track?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

somesoni2
Revered Legend
08-02-2022
07:26 AM
Try this
| rest /servicesNS/-/-/data/ui/views splunk_server=local
| search title="test_dashboard"
| rename eai:acl.app AS app, eai:data AS data
| fields title app author data
| where match(data,"\|\s*savedsearch\s") OR match(data,"ds\.savedSearch") OR match(data,"search ref\=")
| rex field=data "\|\s+savedsearch\s+(?<savedsearch1>\S+)"
| rex field=data "(\s|\")ref((\":)|\=)\s*\"(?<savedsearch2>[^\"]+)"
| eval savedsearch=coalesce(savedsearch1, savedsearch2)
| stats count by savedsearch | fields - count
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

somesoni2
Revered Legend
08-02-2022
06:42 AM
Give this a try
| rest /servicesNS/-/-/data/ui/views splunk_server=local
| search title="test_dashboard"
| rename eai:acl.app AS app, eai:data AS data
| fields title app author data
| where match(data,"\|\s*savedsearch\s") OR match(data,"ds\.savedSearch") OR match(data,"search ref\=")
| rex field=data "\|\s+savedsearch\s+(?<savedsearch1>\S+)"
| rex field=data "(\s|\")ref((\":)|\=)\s*\"(?<savedsearch2>[^\"]+)"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sanz
Explorer
08-02-2022
07:24 AM
@somesoni2 Thanks a lot for you reply! This works like a charm.
Question though:
How can I loop the results as list into 1 field maybe as list?
Something like this (I mixed python and SPL haha)
data[] = results from | where match(data,"\|\s*savedsearch\s") OR match(data,"ds\.savedSearch") OR match(data,"search ref\=")
for x in data:
print(x) in field "savedsearch"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

somesoni2
Revered Legend
08-02-2022
07:26 AM
Try this
| rest /servicesNS/-/-/data/ui/views splunk_server=local
| search title="test_dashboard"
| rename eai:acl.app AS app, eai:data AS data
| fields title app author data
| where match(data,"\|\s*savedsearch\s") OR match(data,"ds\.savedSearch") OR match(data,"search ref\=")
| rex field=data "\|\s+savedsearch\s+(?<savedsearch1>\S+)"
| rex field=data "(\s|\")ref((\":)|\=)\s*\"(?<savedsearch2>[^\"]+)"
| eval savedsearch=coalesce(savedsearch1, savedsearch2)
| stats count by savedsearch | fields - count
