you can use this q uery as reference | rest splunk_server=local /servicesNS/-/-/data/ui/views | rename title AS "Dashboard Name", eai:acl.app AS Application, eai:acl.owner AS Owner, id as dashboard_id | eval dashboard_name=replace(dashboard_id, ".*/data/ui/views/([^/]+)$", "\1") | eval dashboard_name=urldecode(dashboard_name) | fields "Dashboard Name", Application, Owner, dashboard_name | join type=left dashboard_name [ search index=_internal sourcetype IN ("splunk_web_service", "splunkd_access") | rex "Rendering dashboard \\\"(?<rendered_dashboard>[^\"]+)" | eval uri_decode = urldecode(uri) | rex field=uri_decode "data/ui/views/(?<rendered_dashboard>[^$]+)$" | search rendered_dashboard=* NOT rendered_dashboard="_new" | transaction rendered_dashboard maxspan=2s | stats last(_time) AS last_viewed_time BY rendered_dashboard | eval dashboard_name=rendered_dashboard | fields dashboard_name, last_viewed_time ] | eval "Last Viewed Time"=if(isnull(last_viewed_time), "Never Viewed", strftime(last_viewed_time, "%m/%d/%Y %H:%M:%S")) | table "Dashboard Name", Application, Owner, "Last Viewed Time"
... View more