I'm using API call to retrieve results of the job search/jobs/{search_id}/results .
I'm running the following command:
curl -u admin:password -k "https://<HOST>/rest/services/search/jobs/<JOB_NUMBER>/results?count=1&output_mode=json"
But, no matter what, when I put for count param (0, 1, "asadafa", etc.) I get 100 events (which is default value).
Can there be some Splunk server configuration which makes the count parameter ignored? When I run the query on other Splunk instance it works as expected.
Splunk version: 6.6.6
The server which I'm trying connect to has an endpoint https://<HOST>/rest , which probably redirects to Splunk management API port.
... View more