I am looking for an alert when any search in (rest /services/saved/searches splunk_server=local) is being modified.
The configtracker feature of Splunk 9.x can help with that. Start with this query and modify it to suit your needs.
index=_configtracker "data.path"=*savedsearches.conf