Reporting

Is it possible to run a saved search on a remote splunk server using the rest search command?

responsys_cm
Builder

I'm wondering if there is an equivalent way to do this with the rest search command:

curl -k -u admin:changeme -d "search=savedsearch CIF%3Adomain_botnet" -d "output_mode=csv" https://localhost:8089/servicesNS/admin/search/search/jobs/export -o domain_botnet.csv

That runs the saved search called CIF:domain_botnet.

Is that possible?

Thx.

Craig

Tags (3)
0 Karma

MuS
Legend

Hi responsys_cm,

sure, have you seen the saved search REST API docs?

There are also some examples in the SDKs available:
For Java - http://dev.splunk.com/view/java-sdk/SP-CAAAEKY#runsavedargs

For C# - http://dev.splunk.com/view/csharp-sdk/SP-CAAAEQF#runsavedargs

hope this helps ...

cheers, MuS

responsys_cm
Builder

I looked through the API doc, though I'm not a developer...

It would seem that something like this should work:

| rest /servicesNS/craig/saved/searches/InputDomain/dispatch splunk_server=10.10.10.10 get-arg-name="dispatch.now" get-arg-value="true"

But that never gets any results. Nor does it produce any kind of error.

I'm also unclear on how to authenticate to the remote Splunk server using the rest command...

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...