I try to search with comand
| rest /services/app/local
but the value of the "updated" field is "1970-01-01T07:00:00+07:00" for all app
That is a known problem, although I'm not sure it's published. Go to https://ideas.splunk.com to ask Splunk to rectify it.