Splunk Search

Listing all saved searches from all apps via REST without correlation searches

karadikid
Explorer

Hi All,

So, I know I can get a list of all enabled saved searches by doing:

| rest count=0 /servicesNS/-/-/saved/searches | search disabled=0 | table title

However, I want to list all enabled saved searches from all Apps, which are NOT "correlation searches". Any idea how to implement such query?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

A correlation search is the same as a saved search.  The only distinction is the app context.  You can use the regex command to filter on eai:acl.app, but you'll have to come up with a regular expression that matches only ES apps.  Something like this (which filters too much)

| rest count=0 /servicesNS/-/-/saved/searches | search disabled=0 
| regex eai:acl.app!="(DA-ESS)|(SA-)"
| table title

 

---
If this reply helps you, Karma would be appreciated.

karadikid
Explorer

Thanks richgalloway!

So, can I safely assume that a correlation search is only related to SplunkES and simply negate other apps in my queries?

I also wonder how the UI returns specifically "Correlation Searches"\"Saved Searches"\etc... when searching via the "content management" UI. Any idea how I can mimic this behaviour? 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I dug further into my notes and found this query.

| rest splunk_server=local count=0 /services/saved/searches 
| where NOT 'action.correlationsearch.enabled'=1

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...