When we search within Searches, reports and alerts, we get the entire set of items.
What can it be? As we search for API
in this example...
Dear ddrillic: search for something like "nothere" which is unlikely to be in any of your search titles or the actual search. Does that match your searches, reports and alerts? I suggest this because API matched a lot of my searches too and not just the titles.
Hi. If you have the string API in the subject or in the body of the search, it will match.
You see, the problem I have is that everything comes back, including items that don't match...
Hi. What version of Splunk?
So a good test.. search for something like nothere which is unlikely to be in any of your search titles or the actual search. Does that match your searches, reports and alerts? I suggest this because API matched a lot of my searches too and not just the titles.
HI @ddrillic,
Do you have any searches, reports or alerts in "AppName
" app?
Can you please uncheck
"show only objects created in this app context" checkbox? You might be found your desired savedsearches.
Thanks
No luck with that @kamlesh_vaghela.
I also tried searching for API*
but everything comes back.
What does the messages tell you, you have 4 of them?
If you query the REST api directly can you get something back:
| rest /servicesNS/-/-/saved/searches splunk_server=local | search title="api*"