<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: REST API Incomplete Results in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/510401#M142856</link>
    <description>&lt;P&gt;Post the search to&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;https://&amp;lt;host&amp;gt;:&amp;lt;mPort&amp;gt;/servicesNS/userName/appName/search&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jul 2020 11:02:34 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2020-07-22T11:02:34Z</dc:date>
    <item>
      <title>REST API Incomplete Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/509829#M142516</link>
      <description>&lt;P&gt;Getting incomplete (lesser number of events as results ) when using rest API. The same search i run in the splunk enterprise gives 90 events always, but the splunk api returning only 12-14 events(varying). Both the searches have earliest_time=-1d and the exec_mode is oneshot, so i am getting the results back then only.&lt;/P&gt;&lt;P&gt;Here i was using search/jobs api and oneshot mode, so the reuslts were incomplete. I read somewhere and rather used post:search/jobs, get: search/jobs/{sid} in a while loop and then retrieved results, but the results still are incomplete.&lt;/P&gt;&lt;P&gt;Cant&amp;nbsp; seem to find a solution, would be great if anyone could help, my search looks like this, although not sure if it matters.&lt;/P&gt;&lt;P&gt;index="val" [search index="val" field1="val2"&amp;nbsp; &amp;nbsp;|&amp;nbsp; dedup&amp;nbsp; field2&amp;nbsp; |&amp;nbsp; format]&amp;nbsp; eventstats count by field2&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 07:15:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/509829#M142516</guid>
      <dc:creator>vvvinamer</dc:creator>
      <dc:date>2020-07-22T07:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: REST API Incomplete Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/509843#M142520</link>
      <description>&lt;P&gt;Try adding attribute count=0 to you rest query&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;https://&amp;lt;host&amp;gt;:&amp;lt;mPort&amp;gt;/services/search/jobs?sid=&amp;lt;sid&amp;gt;&amp;amp;count=0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 15:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/509843#M142520</guid>
      <dc:creator>arjunpkishore5</dc:creator>
      <dc:date>2020-07-18T15:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: REST API Incomplete Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/509854#M142525</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (7).png" style="width: 981px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9767i9BF2FCD921BE41E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (7).png" alt="Screenshot (7).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for replying but, tried adding that but no change, this time the actual search(a different search than my post) on splunk generated 147 events whereas splunk api got 62 events. Also my search is oneshot and i wasnt able to find the count field in search/jobs post methods.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 16:06:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/509854#M142525</guid>
      <dc:creator>vvvinamer</dc:creator>
      <dc:date>2020-07-18T16:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: REST API Incomplete Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/510400#M142855</link>
      <description>&lt;P&gt;&lt;FONT size="4"&gt;are you adding earliest=-24h to your search in the UI or are you using the time picker to select last 24h? &amp;nbsp;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;try explicitly adding it to your UI search to see if that makes a difference.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;also, verify you are dispatching the REST search in the same app &amp;amp; user context. &amp;nbsp;Use servicesNS endpoints to do that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 10:58:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/510400#M142855</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-07-22T10:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: REST API Incomplete Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/510401#M142856</link>
      <description>&lt;P&gt;Post the search to&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;https://&amp;lt;host&amp;gt;:&amp;lt;mPort&amp;gt;/servicesNS/userName/appName/search&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 11:02:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REST-API-Incomplete-Results/m-p/510401#M142856</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-07-22T11:02:34Z</dc:date>
    </item>
  </channel>
</rss>

