1 |
| rest splunk_server=local /services/apps/local | search update.version=* | table title version update.version |
1 |
<i><span style="font-size: 10.0pt; color: #333333;">update.*</span></i> |
1 |
<i><span style="font-size: 10.0pt; color: #333333;">splunk_server</span></i> |
Got it here: https://answers.splunk.com/answers/336868/has-anyone-created-a-scheduled-search-that-notifie.html