Thanks.. that helped me with the next revision of the script to handle saved searches in addition to views...
| rest /servicesNS/-/-/data/ui/views splunk_server=local
| rename eai:appName as appName, eai:acl.owner as owner, eai:acl.sharing as sharing, eai:data as data, eai:type as type
| fields type, appName, sharing, owner, title, updated, matching_values, data, id
| append
[| rest/servicesNS/-/-/saved/searches splunk_server=local
| eval type="search"
| rename eai:acl.app as appName, eai:acl.owner as owner, qualifiedSearch as data
| fields type, appName, sharing, owner, title, updated, matching_values, data, id
]
| regex data="(?msi)sourcetype\s?=\s?\"?(xml)?wineventlog:[^\s]+"
| rex field=data "(?<matching_values>(?msi)sourcetype\s?=\s?\"?(xml)?wineventlog:[^\s]+)"
| sort 0 appName, type, title
... View more