Is there any way or workaround to list out all the saved/scheduled searches in which it contains an eventtype named "ABC" in its search body?
I am trying to test the impact of newly modified event types and its dependency in any current running search..
Try this
| rest /servicesNS/-/-/saved/searches splunk_server=local | search search="*eventtype=ABC*" | table title search eai:acl.owner eai:acl.app | rename eai:acl.* as *
Well, this worked for me.
Do check if you have not missed the "" , i.e. `|search search="*eventtype=ABC"`
For macro, try the following:
| rest /servicesNS/-/-/admin/macros splunk_server=local |search definition="*eventtype=ABC*"| table title definition
The search resulted no results....It worked untill rest /servicesNS/-/-/saved/searches splunk_server=local but it didnt worked with the | search search="eventtype=ABC"