A Splunk query to inventory all your saved search

| rest /servicesNS/-/-/saved/searches
| search NOT author=nobody NOT disabled=1

The above query will list out all your saved search with their attributes. It’s pretty helpful when we want to know who the user community setting up their alert actions.

Leave a Reply

Your email address will not be published. Required fields are marked *