Hi,
I’m using the rest api with curl now I got the following question:
Is it possible to add parameters to a saved search so I can specify my search by the IP 192.168.178.1 and I get results only with this IP something like:
curl --get -k -u admin:changeme -d "output_mode=csv" -d "count=5" 'search="search IP=192.168.178.1 https://localhost:8089/servicesNS/admin/search/search/jobs/1350986028.108/results
Thanks in Advance
Yes, you can. You can schedule the search job, and supply a post filter when retrieving results. See http://docs.splunk.com/Documentation/Splunk/5.0.2/RESTAPI/RESTsearch#search.2Fjobs.2F.7Bsearch_id.7D...
You should be able to use the exact parameters you used in your example. However, your search string needs to be URL-encoded:
... -d "count=5" -d "search=IP%3D192.168.178.1" https://localhost:8089/../.