OK. if you want to follow just creation, I have a best solution for you with lookup , to recognize new correlations : 1- first run this query just 1 time, to primitive lookup update: | rest /services/saved/searches splunk_server=local count=0 | search author!="admin" AND action.correlationsearch.enabled=1 | table title,author | eval flag=1 | outputlookup test2.csv 2-then make an alert or report and define a time schedule for that with this query to recognize new correlations created during alert/report time period (all titles that there is no flag=1 for them in lookup) : | rest /services/saved/searches splunk_server=local count=0 | search author!="admin" AND action.correlationsearch.enabled=1 | table title,author | lookup test2.csv title as title output flag |search NOT flag=* | eval flag=1 | outputlookup append=T test2.csv as a result this query list for you just new correlations , for example if your time schedule is every day at 7 AM, it lists for you all correlation searches were create between yesterday 7 AM - today 7 AM
... View more