Hi Splunkers,
Is there any way to list all the saved searches in Splunk? I want to export the saved searches details along with the user and scheduled time and etc.
Hi Praveenbandi
Below rest command will help you to get all secheduled searches, to list all the searches run the second search
| rest /servicesNS/-/-/saved/searches | search is_scheduled=1 | table title, cron_schedule next_scheduled_time eai:acl.owner actions eai:acl.app action.email action.email.to dispatch.earliest_time dispatch.latest_time search *
Search to get all saved searches.
| rest /servicesNS/-/-/saved/searches | table title, cron_schedule next_scheduled_time eai:acl.owner actions eai:acl.app action.email action.email.to dispatch.earliest_time dispatch.latest_time search *
to know all the users and their scheduled searches.
| rest /servicesNS/-/-/saved/searches | search is_scheduled=1 | stats values(eai:acl.app) as application c by title, eai:acl.owner | fields - c
| rest /servicesNS/-/-/saved/searches splunk_server=local
As per: https://answers.splunk.com/answers/231694/how-can-i-get-a-list-of-all-saved-searches-from-al.html
Also: https://answers.splunk.com/answers/12488/how-to-list-saved-searches.html
Hi Praveenbandi
Below rest command will help you to get all secheduled searches, to list all the searches run the second search
| rest /servicesNS/-/-/saved/searches | search is_scheduled=1 | table title, cron_schedule next_scheduled_time eai:acl.owner actions eai:acl.app action.email action.email.to dispatch.earliest_time dispatch.latest_time search *
Search to get all saved searches.
| rest /servicesNS/-/-/saved/searches | table title, cron_schedule next_scheduled_time eai:acl.owner actions eai:acl.app action.email action.email.to dispatch.earliest_time dispatch.latest_time search *
to know all the users and their scheduled searches.
| rest /servicesNS/-/-/saved/searches | search is_scheduled=1 | stats values(eai:acl.app) as application c by title, eai:acl.owner | fields - c