<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Run DBX query via REST API in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Run-DBX-query-via-REST-API/m-p/536354#M151649</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;&amp;nbsp;Thank you; but still nothing is being returned after trying for 10 minutes, until eventually an error "Unknown SID" is returned:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[user.name@host ~]$ curl -u username:password -k https://192.168.xx.xxx:xxxx/services/search/jobs/export --data-urlencode search=' | dbxquery query=\"select (select sum(bytes) from dba_data_files)+(select sum(bytes) from dba_temp_files)-(select sum(bytes) from dba_free_space) total_size from dual\" connection=\"xxx\"'
&amp;lt;?xml version='1.0' encoding='UTF-8'?&amp;gt;
&amp;lt;results preview='0'&amp;gt;
&amp;lt;meta&amp;gt;
&amp;lt;fieldOrder /&amp;gt;
&amp;lt;/meta&amp;gt;
&amp;lt;messages&amp;gt;
  &amp;lt;msg type="DEBUG"&amp;gt;Configuration initialization for /opt/splunk/etc took 19ms when dispatching a search (search ID: 1611076520.164004)&amp;lt;/msg&amp;gt;
  &amp;lt;msg type="DEBUG"&amp;gt;The 'dbxquery' command is implemented as an external script and may cause the search to be significantly slower.&amp;lt;/msg&amp;gt;
  &amp;lt;msg type="DEBUG"&amp;gt;search context: user="username", app="search", bs-pathname="/opt/splunk/etc"&amp;lt;/msg&amp;gt;
&amp;lt;/messages&amp;gt;

&amp;lt;/results&amp;gt;

# Querying for result for 10 minutes, until below occurs:

[user.name@host ~]$ curl -u username:password -k https://192.168.xx.xxx:xxxx/services/search/jobs/1611076520.164004/results/ --get -d output_mode=csv
&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;response&amp;gt;
  &amp;lt;messages&amp;gt;
    &amp;lt;msg type="FATAL"&amp;gt;Unknown sid.&amp;lt;/msg&amp;gt;
  &amp;lt;/messages&amp;gt;
&amp;lt;/response&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jan 2021 17:25:15 GMT</pubDate>
    <dc:creator>mxanareckless</dc:creator>
    <dc:date>2021-01-19T17:25:15Z</dc:date>
    <item>
      <title>Run DBX query via REST API</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Run-DBX-query-via-REST-API/m-p/536272#M151621</link>
      <description>&lt;P&gt;I've checked this, but it hasn't solved the problem for me:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-run-a-curl-command-on-a-dbxquery/m-p/500081#M85221" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-run-a-curl-command-on-a-dbxquery/m-p/500081#M85221&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This is my curl request:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;curl -u username:password -k https://192.168.xx.xxx:xxxx/services/search/jobs -d search=" | dbxquery query=\"select (select sum(bytes) from dba_data_files)+(select sum(bytes) from dba_temp_files)-(select sum(bytes) from dba_free_space) total_size from dual\" connection=\"XXX\""&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I get an SID back:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;response&amp;gt;
  &amp;lt;sid&amp;gt;1611013146.153172&amp;lt;/sid&amp;gt;
&amp;lt;/response&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;However when I try fetching the results, I get nothing back:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[user.name@host ~]$ curl -u username:password -k https://192.168.xx.xxx:xxxx/services/search/jobs/1611013146.153172/results/ --get -d output_mode=csv
[user.name@host ~]$&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried waiting a few minutes in between fetch attempts, still nothing. This same query works find and returns a result immediately when run from the DBX UI:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="spk-cb-cxn2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12576i2B14A0ADD63AB3A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="spk-cb-cxn2.PNG" alt="spk-cb-cxn2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there something I'm missing here in order to get the result via the REST API? Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 23:51:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Run-DBX-query-via-REST-API/m-p/536272#M151621</guid>
      <dc:creator>mxanareckless</dc:creator>
      <dc:date>2021-01-18T23:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: Run DBX query via REST API</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Run-DBX-query-via-REST-API/m-p/536334#M151643</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223382"&gt;@mxanareckless&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can try with export endpoint;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;curl -u username:password -k https://192.168.xx.xxx:xxxx/services/search/jobs/export --data-urlencode search=' | dbxquery query=\"select (select sum(bytes) from dba_data_files)+(select sum(bytes) from dba_temp_files)-(select sum(bytes) from dba_free_space) total_size from dual\" connection=\"XXX\"' &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 13:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Run-DBX-query-via-REST-API/m-p/536334#M151643</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-19T13:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Run DBX query via REST API</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Run-DBX-query-via-REST-API/m-p/536354#M151649</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;&amp;nbsp;Thank you; but still nothing is being returned after trying for 10 minutes, until eventually an error "Unknown SID" is returned:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[user.name@host ~]$ curl -u username:password -k https://192.168.xx.xxx:xxxx/services/search/jobs/export --data-urlencode search=' | dbxquery query=\"select (select sum(bytes) from dba_data_files)+(select sum(bytes) from dba_temp_files)-(select sum(bytes) from dba_free_space) total_size from dual\" connection=\"xxx\"'
&amp;lt;?xml version='1.0' encoding='UTF-8'?&amp;gt;
&amp;lt;results preview='0'&amp;gt;
&amp;lt;meta&amp;gt;
&amp;lt;fieldOrder /&amp;gt;
&amp;lt;/meta&amp;gt;
&amp;lt;messages&amp;gt;
  &amp;lt;msg type="DEBUG"&amp;gt;Configuration initialization for /opt/splunk/etc took 19ms when dispatching a search (search ID: 1611076520.164004)&amp;lt;/msg&amp;gt;
  &amp;lt;msg type="DEBUG"&amp;gt;The 'dbxquery' command is implemented as an external script and may cause the search to be significantly slower.&amp;lt;/msg&amp;gt;
  &amp;lt;msg type="DEBUG"&amp;gt;search context: user="username", app="search", bs-pathname="/opt/splunk/etc"&amp;lt;/msg&amp;gt;
&amp;lt;/messages&amp;gt;

&amp;lt;/results&amp;gt;

# Querying for result for 10 minutes, until below occurs:

[user.name@host ~]$ curl -u username:password -k https://192.168.xx.xxx:xxxx/services/search/jobs/1611076520.164004/results/ --get -d output_mode=csv
&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;response&amp;gt;
  &amp;lt;messages&amp;gt;
    &amp;lt;msg type="FATAL"&amp;gt;Unknown sid.&amp;lt;/msg&amp;gt;
  &amp;lt;/messages&amp;gt;
&amp;lt;/response&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 17:25:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Run-DBX-query-via-REST-API/m-p/536354#M151649</guid>
      <dc:creator>mxanareckless</dc:creator>
      <dc:date>2021-01-19T17:25:15Z</dc:date>
    </item>
  </channel>
</rss>

