Hello, Splunk lovers!
I have some questions
What i want:
1. i want to make a table from search history, where time presets were queried by all_time or long diaposone
2. i want find other searches, what have command "outputlookup"
please, help
thank you!
1. Use | history to display your search history. Add | table to view selected fields. What is "long diaposone"?
2. To find saved searches containing the command "outputlookup" try this query
| rest splunk_server=local /servicesNS/-/-/saved/searches
| search search="*outputlookup*"