Splunk Search

Splunk rest API - List "All configurations"

vamsigurram
Path Finder

Hi, 

WHen i go into splunk console --> settings --> "All Configurations", i see 2000+ entries for seach and reporting app.

How do i pull all these rows using rest api?

I want to list all these knowledge objects per author (owner).

I tried something like this, but that did not give all the results.

| rest "/servicesNS/-/search/saved/searches"

 

0 Karma
1 Solution

vamsigurram
Path Finder

Looking at splunk docs, i found the below REST API, gives all the info that "All Configurations"  is giving us.

 

| rest /servicesNS/-/search/directory | search eai:acl.app="search"

 

The only question, i have is why does splunk give me "All configurations" for all the apps, when i clearly mentioned search app, as highlighted above?

Hence i had to limit my results to search app, by doing | search eai:acl.app="search"

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The "All Configurations" page contains far more than saved searches.  To get all of the same information via REST requires multiple calls.

| rest /servicesNS/-/-/search/saved/searches
| rest /servicesNS/-/-/configs/conf-transforms
| rest /servicesNS/-/-/configs/conf-macros
| rest /servicesNS/-/-/configs/conf-commands

This is not a complete list.  The REST manual should have what you need to complete the task.

---
If this reply helps you, Karma would be appreciated.

vamsigurram
Path Finder

Looking at splunk docs, i found the below REST API, gives all the info that "All Configurations"  is giving us.

 

| rest /servicesNS/-/search/directory | search eai:acl.app="search"

 

The only question, i have is why does splunk give me "All configurations" for all the apps, when i clearly mentioned search app, as highlighted above?

Hence i had to limit my results to search app, by doing | search eai:acl.app="search"

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...