<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unexpected status for to fetch REST endpoint uri=https://127.0.0.1:8089/services/storage/investigation/investigation?cou in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unexpected-status-for-to-fetch-REST-endpoint-uri-https-127-0-0-1/m-p/559274#M10057</link>
    <description>&lt;UL&gt;&lt;LI&gt;Unexpected status for to fetch REST endpoint uri=&lt;A href="https://127.0.0.1:8089/services/storage/investigation/investigation?count=0&amp;amp;all=true&amp;amp;earliest=-700d&amp;amp;latest=now&amp;amp;output_mode=xml" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089/services/storage/investigation/investigation?count=0&amp;amp;all=true&amp;amp;earliest=-700d&amp;amp;latest=now&amp;amp;output_mode=xml&lt;/A&gt; from server=&lt;A href="https://127.0.0.1:8089" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089&lt;/A&gt; - Bad Request&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm having an issue with understanding and fixing my REST API. It has worked previously and there's no upgrade that I'm aware of. If I modify the above search from "latest=now" to "latest=-3d" the data returns fine. No new data is being written to this URI. Yesterday "latest=-2d" returned data today it does not. I'm probably not explaining this well but to me it appears that somewhere in the last few days this API URI broke. Any assistance would be appreciated.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jul 2021 14:08:15 GMT</pubDate>
    <dc:creator>jordanmorgan</dc:creator>
    <dc:date>2021-07-13T14:08:15Z</dc:date>
    <item>
      <title>Unexpected status for to fetch REST endpoint uri=https://127.0.0.1:8089/services/storage/investigation/investigation?cou</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unexpected-status-for-to-fetch-REST-endpoint-uri-https-127-0-0-1/m-p/559274#M10057</link>
      <description>&lt;UL&gt;&lt;LI&gt;Unexpected status for to fetch REST endpoint uri=&lt;A href="https://127.0.0.1:8089/services/storage/investigation/investigation?count=0&amp;amp;all=true&amp;amp;earliest=-700d&amp;amp;latest=now&amp;amp;output_mode=xml" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089/services/storage/investigation/investigation?count=0&amp;amp;all=true&amp;amp;earliest=-700d&amp;amp;latest=now&amp;amp;output_mode=xml&lt;/A&gt; from server=&lt;A href="https://127.0.0.1:8089" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089&lt;/A&gt; - Bad Request&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm having an issue with understanding and fixing my REST API. It has worked previously and there's no upgrade that I'm aware of. If I modify the above search from "latest=now" to "latest=-3d" the data returns fine. No new data is being written to this URI. Yesterday "latest=-2d" returned data today it does not. I'm probably not explaining this well but to me it appears that somewhere in the last few days this API URI broke. Any assistance would be appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 14:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unexpected-status-for-to-fetch-REST-endpoint-uri-https-127-0-0-1/m-p/559274#M10057</guid>
      <dc:creator>jordanmorgan</dc:creator>
      <dc:date>2021-07-13T14:08:15Z</dc:date>
    </item>
  </channel>
</rss>

