Looking at your curl, the saved search result you're pulling is at the path USER:APP:test, but that is the generic example I originally provided and probably has to be updated based on your user, app, and report name details. Can you confirm that there is data in the UI? Essentially that curl is just exporting the results of the last run of a saved search. You can do the same search in the UI with | loadjob savedsearch="USER:APP:REPORT" Just replace USER with your username (may need to be the user owner/creator of the report haven't tested extensively), APP with the Splunk app where the report is saved, and REPORT with the name of the report. e.g.: | loadjob savedsearch="bhjohns:engineering:customer configurations" also make sure to extend the time range of the search as I believe it just pulls the last run as long as one exists within the time range, might as well extend longer to start (a few days), and then shrink to where you expect it to be once you get results returning as expected. After you get the UI to return the data you expect, then you can try the curl again and just updated the search param in the curl based on what you see working in the UI
... View more