Splunk Search

Splunk rest API - List "All configurations"

vamsigurram
Path Finder

Hi, 

WHen i go into splunk console --> settings --> "All Configurations", i see 2000+ entries for seach and reporting app.

How do i pull all these rows using rest api?

I want to list all these knowledge objects per author (owner).

I tried something like this, but that did not give all the results.

| rest "/servicesNS/-/search/saved/searches"

 

0 Karma
1 Solution

vamsigurram
Path Finder

Looking at splunk docs, i found the below REST API, gives all the info that "All Configurations"  is giving us.

 

| rest /servicesNS/-/search/directory | search eai:acl.app="search"

 

The only question, i have is why does splunk give me "All configurations" for all the apps, when i clearly mentioned search app, as highlighted above?

Hence i had to limit my results to search app, by doing | search eai:acl.app="search"

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The "All Configurations" page contains far more than saved searches.  To get all of the same information via REST requires multiple calls.

| rest /servicesNS/-/-/search/saved/searches
| rest /servicesNS/-/-/configs/conf-transforms
| rest /servicesNS/-/-/configs/conf-macros
| rest /servicesNS/-/-/configs/conf-commands

This is not a complete list.  The REST manual should have what you need to complete the task.

---
If this reply helps you, Karma would be appreciated.

vamsigurram
Path Finder

Looking at splunk docs, i found the below REST API, gives all the info that "All Configurations"  is giving us.

 

| rest /servicesNS/-/search/directory | search eai:acl.app="search"

 

The only question, i have is why does splunk give me "All configurations" for all the apps, when i clearly mentioned search app, as highlighted above?

Hence i had to limit my results to search app, by doing | search eai:acl.app="search"

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...