Getting Data In

REST API: searching piped into stats, no events available

twinspop
Influencer

If I run this search through the web interface:

error | stats count by host | sort - count

And then venture over to port 8089 and check the job, I can see the search summary and hit the Events link at the bottom of the page to get a list of the events.

However, if I run that search through the REST API, the Events link goes to an empty page. How can I get a list of the events from that search using the REST API?

Thanks, Jon

Tags (3)
0 Karma

twinspop
Influencer

If I set the status_buckets POST variable to 300 (as the is the default from the web interface search), I get eventAvailableCount > 0.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...