Splunk Search

Search rest command for a list of dashboards using saves searches and macros?

uagraw01
Motivator

Hello Splunkers!!

 

I want a list of dashboards and those dashboards are using saved searches & macros. How I can achieve those details by using rest command. So far I have tried the below one but not getting the exact result.

 

|rest /servicesNS/-/-/data/ui/views splunk_server=local |table author eai:acl.app id eai:data title

 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01 ,

what's the problem wit your search? it's correct!

It extracts all views with the code, so you can make two additional field extractions to identify macros and savedsearches:

| rest /servicesNS/-/-/data/ui/views splunk_server=local 
| rex field="eai:data" max_match=0 "\`(?<macro>\w+)\`"
| rex field="eai:data" max_match=0 "savedsearch\s+(?<savedsearch>\w+)"
| table author eai:acl.app id eai:data  macro savedsearch title

Ciao.

Giuseppe

 

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01 ,

what's the problem wit your search? it's correct!

It extracts all views with the code, so you can make two additional field extractions to identify macros and savedsearches:

| rest /servicesNS/-/-/data/ui/views splunk_server=local 
| rex field="eai:data" max_match=0 "\`(?<macro>\w+)\`"
| rex field="eai:data" max_match=0 "savedsearch\s+(?<savedsearch>\w+)"
| table author eai:acl.app id eai:data  macro savedsearch title

Ciao.

Giuseppe

 

Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...