Reporting

Why can't we search within Searches, reports and alerts?

ddrillic
Ultra Champion

When we search within Searches, reports and alerts, we get the entire set of items.

What can it be? As we search for API in this example...

alt text

Tags (1)

burwell
SplunkTrust
SplunkTrust

Dear ddrillic: search for something like "nothere" which is unlikely to be in any of your search titles or the actual search. Does that match your searches, reports and alerts? I suggest this because API matched a lot of my searches too and not just the titles.

0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. If you have the string API in the subject or in the body of the search, it will match.

0 Karma

ddrillic
Ultra Champion

You see, the problem I have is that everything comes back, including items that don't match...

0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. What version of Splunk?

0 Karma

burwell
SplunkTrust
SplunkTrust

So a good test.. search for something like nothere which is unlikely to be in any of your search titles or the actual search. Does that match your searches, reports and alerts? I suggest this because API matched a lot of my searches too and not just the titles.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

HI @ddrillic,

Do you have any searches, reports or alerts in "AppName" app?

Can you please uncheck "show only objects created in this app context" checkbox? You might be found your desired savedsearches.

Thanks

0 Karma

ddrillic
Ultra Champion

No luck with that @kamlesh_vaghela.

I also tried searching for API* but everything comes back.

0 Karma

MuS
Legend

What does the messages tell you, you have 4 of them?

If you query the REST api directly can you get something back:

 | rest /servicesNS/-/-/saved/searches splunk_server=local | search title="api*"
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...