<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unexpected status for to fetch REST endpoint uri=https://127.0.0.1:8089/services/storage/investigation/investigation in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unexpected-status-for-to-fetch-REST-endpoint-uri-https-127-0-0-1/m-p/760450#M12905</link>
    <description>&lt;P&gt;Hi Jordan, Did you ever resolve this? Do you remember how?&lt;BR /&gt;&lt;BR /&gt;I am now experiencing the same issue :'(&lt;/P&gt;</description>
    <pubDate>Fri, 24 Apr 2026 09:45:44 GMT</pubDate>
    <dc:creator>StuartMacL</dc:creator>
    <dc:date>2026-04-24T09:45:44Z</dc:date>
    <item>
      <title>Unexpected status for to fetch REST endpoint uri=https://127.0.0.1:8089/services/storage/investigation/investigation?cou</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unexpected-status-for-to-fetch-REST-endpoint-uri-https-127-0-0-1/m-p/559274#M10057</link>
      <description>&lt;UL&gt;&lt;LI&gt;Unexpected status for to fetch REST endpoint uri=&lt;A href="https://127.0.0.1:8089/services/storage/investigation/investigation?count=0&amp;amp;all=true&amp;amp;earliest=-700d&amp;amp;latest=now&amp;amp;output_mode=xml" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089/services/storage/investigation/investigation?count=0&amp;amp;all=true&amp;amp;earliest=-700d&amp;amp;latest=now&amp;amp;output_mode=xml&lt;/A&gt; from server=&lt;A href="https://127.0.0.1:8089" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089&lt;/A&gt; - Bad Request&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm having an issue with understanding and fixing my REST API. It has worked previously and there's no upgrade that I'm aware of. If I modify the above search from "latest=now" to "latest=-3d" the data returns fine. No new data is being written to this URI. Yesterday "latest=-2d" returned data today it does not. I'm probably not explaining this well but to me it appears that somewhere in the last few days this API URI broke. Any assistance would be appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 14:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unexpected-status-for-to-fetch-REST-endpoint-uri-https-127-0-0-1/m-p/559274#M10057</guid>
      <dc:creator>jordanmorgan</dc:creator>
      <dc:date>2021-07-13T14:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected status for to fetch REST endpoint uri=https://127.0.0.1:8089/services/storage/investigation/investigation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unexpected-status-for-to-fetch-REST-endpoint-uri-https-127-0-0-1/m-p/760450#M12905</link>
      <description>&lt;P&gt;Hi Jordan, Did you ever resolve this? Do you remember how?&lt;BR /&gt;&lt;BR /&gt;I am now experiencing the same issue :'(&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 09:45:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unexpected-status-for-to-fetch-REST-endpoint-uri-https-127-0-0-1/m-p/760450#M12905</guid>
      <dc:creator>StuartMacL</dc:creator>
      <dc:date>2026-04-24T09:45:44Z</dc:date>
    </item>
  </channel>
</rss>

