Splunk Search

Retreive list of alerts shared at app level

rupasri
Observer

Can I retrieve list of alerts shared in App level, Is it possible?

|rest /services/saved/searches 
| search eai:acl.app=my_app eai:acl.sharing=app

| fields eai:acl.owner eai:acl.app eai:acl.sharing search title cron_schedule description
Labels (1)
Tags (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Your search should have given you the results.  Anything unexpected happens when you run the search?  The most I can think of is to search for only scheduled and enabled searches.

| rest /services/saved/searches
| seach eai:acl.app = myapp eai.acl.sharing = app
  is_scheduled = 1 disabled = 0
| fields eai:acl.owner eai:acl.app eai:acl.sharing search title cron_schedule description

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...