<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get the job's log file from client by REST API? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-the-job-s-log-file-from-client-by-REST-API/m-p/330428#M93468</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Did you search &lt;CODE&gt;index=_internal&lt;/CODE&gt; logs for that client? &lt;/P&gt;</description>
    <pubDate>Tue, 23 Jan 2018 04:34:32 GMT</pubDate>
    <dc:creator>p_gurav</dc:creator>
    <dc:date>2018-01-23T04:34:32Z</dc:date>
    <item>
      <title>How to get the job's log file from client by REST API?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-the-job-s-log-file-from-client-by-REST-API/m-p/330427#M93467</link>
      <description>&lt;P&gt;I made a big POST(REST API) request to "services/search/jobs" by collect with index and marker, it will return a sid. The job is taking too long(&amp;gt; 6hrs). I know I can query the status by /services/search/jobs/${sid}. But it cannot provide more information for debugging. How can I get this job's log file(/var/log/splunk/searchs.log etc ) from client?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 22:19:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-the-job-s-log-file-from-client-by-REST-API/m-p/330427#M93467</guid>
      <dc:creator>jenniferhao</dc:creator>
      <dc:date>2018-01-22T22:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to get the job's log file from client by REST API?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-the-job-s-log-file-from-client-by-REST-API/m-p/330428#M93468</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Did you search &lt;CODE&gt;index=_internal&lt;/CODE&gt; logs for that client? &lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 04:34:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-the-job-s-log-file-from-client-by-REST-API/m-p/330428#M93468</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-01-23T04:34:32Z</dc:date>
    </item>
  </channel>
</rss>

