<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search a query on splunk using the rest api in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539191#M90333</link>
    <description>&lt;P&gt;but, we are supposed to use splunk for monitoring the logs, as per client&lt;/P&gt;</description>
    <pubDate>Tue, 09 Feb 2021 15:25:52 GMT</pubDate>
    <dc:creator>vagdevi</dc:creator>
    <dc:date>2021-02-09T15:25:52Z</dc:date>
    <item>
      <title>search a query on splunk using the rest api</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539178#M90329</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I want to create a rest api request to create a search in splunk and get the details(logs) of the search result. I have gone through the splunk document provided by the splunk team, but couldn't get the response properly. I am trying all the ways to hit splunk and search, but it isn't work. I am using basic auth for the request in postman .Please help me to get through this. I am attaching the splunk we are using and the search query we have to use and also the postman request to hit the same&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vagdevi_3-1612878827028.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12861i81BF87A27A982A09/image-size/large?v=v2&amp;amp;px=999" role="button" title="vagdevi_3-1612878827028.png" alt="vagdevi_3-1612878827028.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vagdevi_2-1612878694918.png" style="width: 918px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12860iB436608005EB5B31/image-size/large?v=v2&amp;amp;px=999" role="button" title="vagdevi_2-1612878694918.png" alt="vagdevi_2-1612878694918.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to use only postman for the search, not a curl command.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 13:55:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539178#M90329</guid>
      <dc:creator>vagdevi</dc:creator>
      <dc:date>2021-02-09T13:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: search a query on splunk using the rest api</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539187#M90332</link>
      <description>&lt;P&gt;Better to use different tool and leave Splunk all alone. Not worth even trying. Awful community. Awful UI/UX, almost imaginary docs..........&lt;/P&gt;&lt;P&gt;Also I wouldnt risk downloading files from them (if you are thinking of self-hosting this ).&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 15:13:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539187#M90332</guid>
      <dc:creator>awslabspl</dc:creator>
      <dc:date>2021-02-09T15:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: search a query on splunk using the rest api</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539191#M90333</link>
      <description>&lt;P&gt;but, we are supposed to use splunk for monitoring the logs, as per client&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 15:25:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539191#M90333</guid>
      <dc:creator>vagdevi</dc:creator>
      <dc:date>2021-02-09T15:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: search a query on splunk using the rest api</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539215#M90337</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231367"&gt;@vagdevi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Please try with jobs/export endpoint like below, it will work with basic or bearer token auth.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;https://splunk_server:8089/services/search/jobs/export?search=search index=_internal earliest=-1d latest=now | stats count by host&amp;amp;output_mode=json&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 18:30:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539215#M90337</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-09T18:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: search a query on splunk using the rest api</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539877#M90411</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply&lt;/P&gt;&lt;P&gt;I tried the query you provide, but couldn't get the output. It says error not found.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 08:25:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539877#M90411</guid>
      <dc:creator>vagdevi</dc:creator>
      <dc:date>2021-02-15T08:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: search a query on splunk using the rest api</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539923#M90414</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231367"&gt;@vagdevi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I am attaching the postman screenshot with a working example. Please check what is different?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scelikok_0-1613388338910.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12944i22EE18EE7EE6B1BE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="scelikok_0-1613388338910.png" alt="scelikok_0-1613388338910.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scelikok_1-1613388398784.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12945iCD37DF138F2D6819/image-size/medium?v=v2&amp;amp;px=400" role="button" title="scelikok_1-1613388398784.png" alt="scelikok_1-1613388398784.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 11:26:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539923#M90414</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-15T11:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: search a query on splunk using the rest api</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539964#M90416</link>
      <description>&lt;P&gt;Thanks for the screenshots, but i want to have the logs out from splunk thru postman, not just the count,&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 14:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539964#M90416</guid>
      <dc:creator>vagdevi</dc:creator>
      <dc:date>2021-02-15T14:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: search a query on splunk using the rest api</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539969#M90418</link>
      <description>&lt;P&gt;I used a sample simple search that is short and &amp;nbsp;can run anywhere. Screenshots are for you to compare with yours since you told your getting "error not found".&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing you need to do is change the search parameter value with your search. You should see your results in postman.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 14:36:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/search-a-query-on-splunk-using-the-rest-api/m-p/539969#M90418</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-15T14:36:08Z</dc:date>
    </item>
  </channel>
</rss>

