Splunk Search

Splunk rest API - List "All configurations"

vamsigurram
Path Finder

Hi, 

WHen i go into splunk console --> settings --> "All Configurations", i see 2000+ entries for seach and reporting app.

How do i pull all these rows using rest api?

I want to list all these knowledge objects per author (owner).

I tried something like this, but that did not give all the results.

| rest "/servicesNS/-/search/saved/searches"

 

0 Karma
1 Solution

vamsigurram
Path Finder

Looking at splunk docs, i found the below REST API, gives all the info that "All Configurations"  is giving us.

 

| rest /servicesNS/-/search/directory | search eai:acl.app="search"

 

The only question, i have is why does splunk give me "All configurations" for all the apps, when i clearly mentioned search app, as highlighted above?

Hence i had to limit my results to search app, by doing | search eai:acl.app="search"

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The "All Configurations" page contains far more than saved searches.  To get all of the same information via REST requires multiple calls.

| rest /servicesNS/-/-/search/saved/searches
| rest /servicesNS/-/-/configs/conf-transforms
| rest /servicesNS/-/-/configs/conf-macros
| rest /servicesNS/-/-/configs/conf-commands

This is not a complete list.  The REST manual should have what you need to complete the task.

---
If this reply helps you, Karma would be appreciated.

vamsigurram
Path Finder

Looking at splunk docs, i found the below REST API, gives all the info that "All Configurations"  is giving us.

 

| rest /servicesNS/-/search/directory | search eai:acl.app="search"

 

The only question, i have is why does splunk give me "All configurations" for all the apps, when i clearly mentioned search app, as highlighted above?

Hence i had to limit my results to search app, by doing | search eai:acl.app="search"

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...