Splunk Search

Is there a method to provide the app context to a CLI export search?

Lucas_K
Motivator

Is there a method that I can provide the app context to a cli export search?

I have a savedsearch called "GetLogins" which is in the app "myapp". I don't want to make it global as all the field extractions etc are inside that app.

My guessed curl command is :

curl -k -u admin:changeme https://mysplunk:8089/services/search/jobs/export --data-urlencode  search='| savedsearch GetLogins' -d output_mode=raw -d earliest_time=-1d@d -d latest_time=@d -d app=myapp

The param "app" doesn't work. Is there anyway I can pass an app context to the search? Normally in a url there would be the app context but for the export command there is no /services/app/myapp/search/jobs/export (or similar) path that I can find.

0 Karma

joshd
Builder

Hi Lucas,

This is where a bit of confusion lies in what you would think the parameter you are looking for is called and what it is actually called...

The 'namespace' parameter will define the application context in which it is to run. Its definitely not clear in the REST endpoint doc but you can understand namespace here:

http://docs.splunk.com/Documentation/Splunk/6.4.0/RESTUM/RESTusing#Namespace

Which you can then see is an available parameter to the REST endpoint you are calling:

http://docs.splunk.com/Documentation/Splunk/6.4.0/RESTREF/RESTsearch#search.2Fjobs.2Fexport

Give it a shot and you should get your desired output.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...