<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: expose alerts with API in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500051#M8902</link>
    <description>&lt;P&gt;thanks. i already read it. maybe im missing something but it is not working&lt;/P&gt;</description>
    <pubDate>Mon, 03 Feb 2020 15:27:40 GMT</pubDate>
    <dc:creator>sarit_s</dc:creator>
    <dc:date>2020-02-03T15:27:40Z</dc:date>
    <item>
      <title>expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500045#M8896</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;How can I expose alerts using the API ?&lt;BR /&gt;
i've created a saved searches.&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2020 17:31:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500045#M8896</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-02-02T17:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500046#M8897</link>
      <description>&lt;P&gt;Can you please provide some more info ? What you want to do with alerts using REST API  For example: Modify or Run ?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 15:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500046#M8897</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-02-03T15:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500047#M8898</link>
      <description>&lt;P&gt;run. the same as it will be with the console &lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 15:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500047#M8898</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-02-03T15:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500048#M8899</link>
      <description>&lt;P&gt;Have a look at Splunk SDK  document &lt;A href="https://dev.splunk.com/enterprise/docs/python/sdk-python/howtousesplunkpython/howtorunsearchespython/"&gt;https://dev.splunk.com/enterprise/docs/python/sdk-python/howtousesplunkpython/howtorunsearchespython/&lt;/A&gt; (SDK available in Python, C#, Java &amp;amp; Javascript)&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 15:05:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500048#M8899</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-02-03T15:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500049#M8900</link>
      <description>&lt;P&gt;thanks, it is an interesting option but it is not what im looking for. &lt;BR /&gt;
i need to run it with some tool like postman&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 15:12:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500049#M8900</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-02-03T15:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500050#M8901</link>
      <description>&lt;P&gt;Have a look at Job Export REST API &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/RESTREF/RESTsearch#search.2Fjobs.2Fexport"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.1/RESTREF/RESTsearch#search.2Fjobs.2Fexport&lt;/A&gt; and old answer &lt;A href="https://answers.splunk.com/answers/596185/doing-search-through-rest-api-using-postman-giving.html"&gt;https://answers.splunk.com/answers/596185/doing-search-through-rest-api-using-postman-giving.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 15:19:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500050#M8901</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-02-03T15:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500051#M8902</link>
      <description>&lt;P&gt;thanks. i already read it. maybe im missing something but it is not working&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 15:27:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500051#M8902</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-02-03T15:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500052#M8903</link>
      <description>&lt;P&gt;In that case you need to provide more details, what have you tried  (Like which REST API are you using with search query), what errors are you getting.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 15:30:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500052#M8903</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-02-03T15:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500053#M8904</link>
      <description>&lt;P&gt;i don't see an option to run the alert. i see an option to see the fired alerts or alerts actions.&lt;BR /&gt;
get you please give me an example of how to run an alert ? even from command line&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 15:50:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500053#M8904</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-02-03T15:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500054#M8905</link>
      <description>&lt;P&gt;I don't have postman installed so can't give you postman example but if you look at documentation &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/RESTREF/RESTsearch#search.2Fjobs.2Fexport"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.1/RESTREF/RESTsearch#search.2Fjobs.2Fexport&lt;/A&gt;, they have provided below example&lt;/P&gt;

&lt;P&gt;curl -k -u admin:password &lt;A href="https://splunkserver:8089/services/search/jobs/export"&gt;https://splunkserver:8089/services/search/jobs/export&lt;/A&gt; -d search="savedsearch \ MySavedSearch%20host%3Dwolverine*" &lt;/P&gt;

&lt;P&gt;Additionally have a look at &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/RESTTUT/RESTsearches"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.1/RESTTUT/RESTsearches&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 09:07:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500054#M8905</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-02-04T09:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500055#M8906</link>
      <description>&lt;P&gt;im getting this error :&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;curl: (6) Could not resolve host: splunkserver&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 04 Feb 2020 11:49:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500055#M8906</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-02-04T11:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500056#M8907</link>
      <description>&lt;P&gt;You need to replace &lt;CODE&gt;splunkserver&lt;/CODE&gt; with your actual splunk server hostname or ip address.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 14:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500056#M8907</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-02-04T14:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: expose alerts with API</title>
      <link>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500057#M8908</link>
      <description>&lt;P&gt;ohhh oopssss&lt;BR /&gt;
but anyway, im getting an error:&lt;BR /&gt;
this is my command:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;curl -k -u admin:1qaz@wsx &lt;A href="https://localhost:8089/services/search/jobs/export"&gt;https://localhost:8089/services/search/jobs/export&lt;/A&gt; -d search="savedsearch \ DeletedLuckyCart"&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;this is the error :&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Error in 'savedsearch' command: Unable to find saved search named '\'.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 04 Feb 2020 17:05:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/expose-alerts-with-API/m-p/500057#M8908</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-02-04T17:05:46Z</dc:date>
    </item>
  </channel>
</rss>

