I want a search that will list all objects and their permissions so that I can audit who can read / write to each item quickly. This is as far as I got, but it will not show me obejcts for most of my custom apps:
| rest /services/directory | search eai:acl.app!="system" eai:acl.app!="search" | table title splunk_server eai:acl.app eai:location eai:type eai:acl.owner eai:acl.perms.read eai:acl.perms.write eai:acl.sharing updated