I am trying to identify the saved searches enabled with email notification. We have hunderds of saved searches but only few of them enaled for email notification. Is there a way i can query to find the list instead of going to each and every search and looking manually for email enable option.
One way is by using Splunk's rest
command:
| rest /servicesNS/-/-/saved/searches
| search is_scheduled=1 AND action.email=1
| table title, eai:acl.app, eai:acl.owner, *schedule* action.email.to
Thanks! Please click the checkbox to the left to accept the answer.
It works fine. Thanks!