| rest /services/alerts/fired_alerts splunk_server=local| table eai:acl.app eai:acl.owner id title triggered_alert_count | rename eai:acl.* as *, app as App, owner as Owner, id as Endpoint, title as Title, triggered_alert_count as "Count of Triggered Alerts"
0 comments
| rest /services/data/transforms/extractions | table eai:acl.app, title, SOURCE_KEY, REGEX, FORMAT, DEST_KEY | sort eai:acl.app title | eval DEST_KEY=if(DEST_KEY="","N/A",DEST_KEY) | rename eai:acl.app as App, title as Title, SOURCE_KEY as "Source Key", REGEX as RegEx, FORMAT as Format, DEST_KEY as "Dest Key"
0 comments
| rest /services/data/props/extractions | table stanza type attribute value | sort stanza
0 comments
| rest /services/data/inputs/all | table index source sourcetype title starttime endtime interval | eval interval=if(isnull(interval),"Not a scripted input",interval) | fillnull value="Null" | eval starttime=strftime(starttime,"%b %d, %Y %H:%M:%S"), endtime=strftime(endtime,"%b %d, %Y %H:%M:%S") | rename index as Index, source as Source, sourcetype as Sourcetype, title as Title, starttime as "First Event" endtime as "Latest Event", interval as Interval
0 comments
| rest /services/server/status/resource-usage/hostwide | eval cpu_count = if(isnull(cpu_count), "N/A", cpu_count), cpu_usage = (cpu_system_pct + cpu_user_pct), mem_used_pct = round((mem_used/mem)*100 , 2), mem_used = tostring(round(mem_used/1024, 3),"commas"), mem = tostring(round(mem/1024, 0),"commas") | fields splunk_server, cpu_count, cpu_usage, mem, mem_used, mem_used_pct | sort - cpu_usage, - mem_used_pct | rename splunk_server AS "Splunk Server", cpu_count AS "CPU Cores", cpu_usage AS "CPU Used (%)", mem AS "Memory Capacity (GB)", mem_used AS "Memory Used (GB)", mem_used_pct AS "Memory Used (%)"
0 comments
| rest /services/data/transforms/lookups | table eai:acl.app filename title fields_list id | rename eai:acl.app as App, filename as "Lookup File", title as Title, fields_list as "Fields", id as Endpoint
0 comments
| rest /services/server/roles | table splunk_server role_list
0 comments
| rest /servicesNS/-/-/authorization/roles count=0 splunk_server=local | fields title, capabilities
0 comments
| rest /servicesNS/-/-/authorization/roles count=0 splunk_server=local | fields title,srchIndexesAllowed | rename srchIndexesAllowed as Indexes, title as Role | search Indexes=*
0 comments
| rest /servicesNS/-/-/data/indexes count=0 | where disabled=0 | fields title | rename title as index | join index type=left [ | rest /servicesNS/-/-/authorization/roles count=0 splunk_server=local | fields title,srchIndexesAllowed | rename srchIndexesAllowed as index, title as role | mvexpand index | where NOT match(index,".*\*.*") ] | search role=*
0 comments