In order to administer ES better am trying to find the queries, searches an app makes in addition to what data models it uses. Thank u for your help in advance.
Searches are at: $SPLUNK_HOME/etc/apps/your_app_name/default/savedsearches.conf
Datamodels are at: $SPLUNK_HOME/etc/apps/your_app_name/default/datamodels.conf
You may also find one or both in the local directory, depending on if either is changed/customized.
There are also REST endpoints you can query for more info on scheduled/saved searchs:
| rest /servicesNS/-/your_app_name/saved/searches
| rest /servicesNS/your_user_name/your_app_name/saved/searches