Splunk Search

Is there a method to provide the app context to a CLI export search?

Lucas_K
Motivator

Is there a method that I can provide the app context to a cli export search?

I have a savedsearch called "GetLogins" which is in the app "myapp". I don't want to make it global as all the field extractions etc are inside that app.

My guessed curl command is :

curl -k -u admin:changeme https://mysplunk:8089/services/search/jobs/export --data-urlencode  search='| savedsearch GetLogins' -d output_mode=raw -d earliest_time=-1d@d -d latest_time=@d -d app=myapp

The param "app" doesn't work. Is there anyway I can pass an app context to the search? Normally in a url there would be the app context but for the export command there is no /services/app/myapp/search/jobs/export (or similar) path that I can find.

0 Karma

joshd
Builder

Hi Lucas,

This is where a bit of confusion lies in what you would think the parameter you are looking for is called and what it is actually called...

The 'namespace' parameter will define the application context in which it is to run. Its definitely not clear in the REST endpoint doc but you can understand namespace here:

http://docs.splunk.com/Documentation/Splunk/6.4.0/RESTUM/RESTusing#Namespace

Which you can then see is an available parameter to the REST endpoint you are calling:

http://docs.splunk.com/Documentation/Splunk/6.4.0/RESTREF/RESTsearch#search.2Fjobs.2Fexport

Give it a shot and you should get your desired output.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...