Splunk Search

Search rest command for a list of dashboards using saves searches and macros?

uagraw01
Motivator

Hello Splunkers!!

 

I want a list of dashboards and those dashboards are using saved searches & macros. How I can achieve those details by using rest command. So far I have tried the below one but not getting the exact result.

 

|rest /servicesNS/-/-/data/ui/views splunk_server=local |table author eai:acl.app id eai:data title

 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01 ,

what's the problem wit your search? it's correct!

It extracts all views with the code, so you can make two additional field extractions to identify macros and savedsearches:

| rest /servicesNS/-/-/data/ui/views splunk_server=local 
| rex field="eai:data" max_match=0 "\`(?<macro>\w+)\`"
| rex field="eai:data" max_match=0 "savedsearch\s+(?<savedsearch>\w+)"
| table author eai:acl.app id eai:data  macro savedsearch title

Ciao.

Giuseppe

 

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01 ,

what's the problem wit your search? it's correct!

It extracts all views with the code, so you can make two additional field extractions to identify macros and savedsearches:

| rest /servicesNS/-/-/data/ui/views splunk_server=local 
| rex field="eai:data" max_match=0 "\`(?<macro>\w+)\`"
| rex field="eai:data" max_match=0 "savedsearch\s+(?<savedsearch>\w+)"
| table author eai:acl.app id eai:data  macro savedsearch title

Ciao.

Giuseppe

 

Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 4)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security ...

Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower ...