Splunk Search
Highlighted

Why can't I find savedsearches over REST with permissions set to "App" ?

Explorer

We want to run a couple analyses over all our savedsearches in a particular app. The permissions of these savedsearches are all set to "App". As a user with all necessary privileges I'm able to see and run the searches in this app.

Althought, if I run the following search command to see the details of my savedsearches I dont get any results:

| rest /services/saved/searches | search eai:acl.app=myApp

If I change the permissions of the savedsearch to "Global" it will show up.
Do I miss anything? Or is this as designed and rest search command only shows "Global" objects?

Due to security reasons I'm not able to keep the searches global so we need to find an other solution for that..

Thanks!

0 Karma
Highlighted

Re: Why can't I find savedsearches over REST with permissions set to "App" ?

Builder

Hi,

If you see the search job properties in job manager, by default, the above search looks for searches which are having sharing as global. Following is the sample:

{
    "app": "myapp", 
    "can_write": "1", 
    "modifiable": "1", 
    "owner": "admin", 
    "perms": {
        "read": [
            "admin"
        ], 
        "write": [
            "admin"
        ]
    }, 
    "sharing": "global", 
    "ttl": "600"
}

Try the answer provided for http://answers.splunk.com/answers/210410/how-do-i-list-all-the-saved-searches-for-an-app-in.html

Thanks!!

View solution in original post

Highlighted

Re: Why can't I find savedsearches over REST with permissions set to "App" ?

Explorer

using servicesNS instead of services worked! thanks!

Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.