Splunk Search

Is there a method to provide the app context to a CLI export search?

Lucas_K
Motivator

Is there a method that I can provide the app context to a cli export search?

I have a savedsearch called "GetLogins" which is in the app "myapp". I don't want to make it global as all the field extractions etc are inside that app.

My guessed curl command is :

curl -k -u admin:changeme https://mysplunk:8089/services/search/jobs/export --data-urlencode  search='| savedsearch GetLogins' -d output_mode=raw -d earliest_time=-1d@d -d latest_time=@d -d app=myapp

The param "app" doesn't work. Is there anyway I can pass an app context to the search? Normally in a url there would be the app context but for the export command there is no /services/app/myapp/search/jobs/export (or similar) path that I can find.

0 Karma

joshd
Builder

Hi Lucas,

This is where a bit of confusion lies in what you would think the parameter you are looking for is called and what it is actually called...

The 'namespace' parameter will define the application context in which it is to run. Its definitely not clear in the REST endpoint doc but you can understand namespace here:

http://docs.splunk.com/Documentation/Splunk/6.4.0/RESTUM/RESTusing#Namespace

Which you can then see is an available parameter to the REST endpoint you are calling:

http://docs.splunk.com/Documentation/Splunk/6.4.0/RESTREF/RESTsearch#search.2Fjobs.2Fexport

Give it a shot and you should get your desired output.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...