Is there any way to list out all the saved searches, macros, tags,etc which have a source=ABC in a search?
Is there any search where i can list them?
Or what could be the grep command to check in the backend Linux environment?
Like this in the OS:
find $SPLUNK_HOME/etc -name "*.conf" -exec egrep -l "source=ABC|source = ABC|source= ABC|source =ABC" {} \;
Like this in the OS:
find $SPLUNK_HOME/etc -name "*.conf" -exec egrep -l "source=ABC|source = ABC|source= ABC|source =ABC" {} \;
Thank you for the Answer. What if i am not sure about the source field. I mean it could be renamed with some other names. Then How can i check there If I am not exactly sure about the name of the source field?
Just use "=ABC|= ABC"
instead.