<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Empty results from rest call in Report in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367255#M66760</link>
    <description>&lt;P&gt;The search is owned by me. I modified as shown &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Show to Owner: works for owner, others don't see it.&lt;/LI&gt;
&lt;LI&gt;Shared to App, runs as Owner, All R&amp;amp;W: works for owner, others see it amongst Searches but shows no email.&lt;/LI&gt;
&lt;LI&gt;Shared to App, run as User, All R&amp;amp;W: works for owner, others see it amongst Searches but shows no email.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;It works in the last configuration if I login as "admin", and admin's email address is shown. But not for other logins.&lt;/P&gt;

&lt;P&gt;As admin I tried to share the report to all Apps (Global), same behavior: for normal users the saved search returns nothing.&lt;/P&gt;

&lt;P&gt;The "Inspect &amp;gt; Search log" for a working and a non-working case is the same.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jun 2017 10:07:57 GMT</pubDate>
    <dc:creator>felipetesta</dc:creator>
    <dc:date>2017-06-22T10:07:57Z</dc:date>
    <item>
      <title>Empty results from rest call in Report</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367252#M66757</link>
      <description>&lt;P&gt;Hello.&lt;BR /&gt;
Running 6.6 (paid license) with LDAP authentication. I need to use my own email in a Report. I built a complex search that works, but once it is run as a Report the "| rest" call returns empty. So I tried to save a simpler search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rest /services/authentication/current-context | fields + email 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When I run it in the free search it returns my address. When I run the Report it returns no data.&lt;/P&gt;

&lt;P&gt;Is there something that prevents rest calls in saved searches? Is it a problem with permissions? (but in the simplest test case I am using my own account).&lt;/P&gt;

&lt;P&gt;Help.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 09:03:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367252#M66757</guid>
      <dc:creator>felipetesta</dc:creator>
      <dc:date>2017-06-21T09:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Empty results from rest call in Report</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367253#M66758</link>
      <description>&lt;P&gt;Additional info. The big plan is to allow any user to authenticate on Splunk and see a read-only dashboard with an analysis of her/his operations as found in indexed logs (such as Country of last access, incoming/outgoing email/antispam statistics, ...). I need to determine their email address automatically and I think there's no other way than the REST call to current-context.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 09:31:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367253#M66758</guid>
      <dc:creator>felipetesta</dc:creator>
      <dc:date>2017-06-21T09:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Empty results from rest call in Report</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367254#M66759</link>
      <description>&lt;P&gt;i'm unaware of any permissions/capabilities that would cause this issue. i just ran a super simple search and saved as a report and it seems to work for me, however. &lt;BR /&gt;
    |makeresults|eval data="testdata"|appendcols [| rest /services/authentication/current-context |fields email]&lt;/P&gt;

&lt;P&gt;who owns the report? the report (and therefore the rest) will run as the owner of the report, i believe.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 17:57:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367254#M66759</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-06-21T17:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Empty results from rest call in Report</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367255#M66760</link>
      <description>&lt;P&gt;The search is owned by me. I modified as shown &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Show to Owner: works for owner, others don't see it.&lt;/LI&gt;
&lt;LI&gt;Shared to App, runs as Owner, All R&amp;amp;W: works for owner, others see it amongst Searches but shows no email.&lt;/LI&gt;
&lt;LI&gt;Shared to App, run as User, All R&amp;amp;W: works for owner, others see it amongst Searches but shows no email.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;It works in the last configuration if I login as "admin", and admin's email address is shown. But not for other logins.&lt;/P&gt;

&lt;P&gt;As admin I tried to share the report to all Apps (Global), same behavior: for normal users the saved search returns nothing.&lt;/P&gt;

&lt;P&gt;The "Inspect &amp;gt; Search log" for a working and a non-working case is the same.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 10:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367255#M66760</guid>
      <dc:creator>felipetesta</dc:creator>
      <dc:date>2017-06-22T10:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Empty results from rest call in Report</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367256#M66761</link>
      <description>&lt;P&gt;Could be some funky issue with reports. Have you tried just using this search on the dashboard to set a token?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 12:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367256#M66761</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2017-06-22T12:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Empty results from rest call in Report</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367257#M66762</link>
      <description>&lt;P&gt;Indeed, looks like an issue with reports. I inserted the full search query into a dashboard panel, gave it full visibility and it finally worked. I tested with three different users. Solved.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 14:27:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Empty-results-from-rest-call-in-Report/m-p/367257#M66762</guid>
      <dc:creator>felipetesta</dc:creator>
      <dc:date>2017-06-23T14:27:28Z</dc:date>
    </item>
  </channel>
</rss>

