Getting Data In

saved searches

Siddharthnegi
Contributor

i want to get list of scheduled saved searches with the name and the searches itself. can anybody help?

Labels (1)
0 Karma

jayanta2022
Observer

| rest /servicesNS/-/-/saved/searches splunk_server=local

 

Getting all of your stored searches from the Search Head will be much easier with this.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Start here

 

| rest "/servicesNS/-/-/saved/searches" splunk_server=local search="is_scheduled=1"
| rename eai:* as * acl.app as app
| fields title app author type search

 

that will give you the data, then do what you need to do with it

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...