To reduce duplication of efforts and clean up resource-intensive searches, I am trying to output a list of all saved searches, including the following attributes -
I have used the Splunk btool command, which provided everything except for the search owner. Is there any way to obtain this info?
This should get you started :
| rest /servicesNS/-/-/saved/searches | fields title *owner* *search* *schedule*
Run from the search bar
This should get you started :
| rest /servicesNS/-/-/saved/searches | fields title *owner* *search* *schedule*
Run from the search bar
This worked great. I had to add the count argument to see them all, but this is exactly what we needed. thanks!