<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPLUNK output from search query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554118#M157309</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need help with one more thing, is it possible to retrieve the data from SPLUNK search from a date? For e.g if I need the payload logs from April is it possible to download them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all your help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Avanti&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jun 2021 15:48:03 GMT</pubDate>
    <dc:creator>abidkar</dc:creator>
    <dc:date>2021-06-02T15:48:03Z</dc:date>
    <item>
      <title>SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552103#M156681</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to search the splunk log but I am getting the output in payload format. is there a way I can get it in tabular format instead of payload which I can use to directly insert in the table? Can someone please help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;Avanti&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 21:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552103#M156681</guid>
      <dc:creator>abidkar</dc:creator>
      <dc:date>2021-05-18T21:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552117#M156686</link>
      <description>&lt;P&gt;We need more information to better help you.&amp;nbsp; How exactly are you running the query?&amp;nbsp; Is it in the UI, SDK, API, or other means?&amp;nbsp; What is a "payload format"?&amp;nbsp; The UI will display results in table form by default so if you're not getting that then we'll need to hear about what you're doing and the results you get.&amp;nbsp; A screenshot may be helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 23:34:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552117#M156686</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-18T23:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552120#M156687</link>
      <description>&lt;P&gt;Here is the out put I am getting&lt;/P&gt;&lt;P&gt;{"socClassifVvCode":"XX","logicalDate":"20210518","billingAccountId":"XXXXXXXXX","lastUpdateDate":"20210518181503","msisdn":null,"subStatus":null,"lastUpdateStamp":2245,"deepEventName":"XXXXXXXXXX","deepEventId":"2XXXXXXXX","action":"XXX","effectiveDate":"2021-05-18T17:00:00.000Z","channelId":"XX","productType":null,"requiredSoc":null} ]&lt;/P&gt;&lt;P&gt;However I want in tabular format column wise for e.g.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ClassifCode|Date|AcctID&lt;/P&gt;&lt;P&gt;XX|XX|XXXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I may not be able to paste the actual query but sample encrypted one is as below:&lt;/P&gt;&lt;P&gt;index=adms RestLoggingUtil XXXXXXXXXXX "/XXXXXXXXXXXXXX"| table BAN, PAYLOAD&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 01:56:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552120#M156687</guid>
      <dc:creator>abidkar</dc:creator>
      <dc:date>2021-05-19T01:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552143#M156693</link>
      <description>&lt;P&gt;Use spath to extract the fields from the payload&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 07:57:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552143#M156693</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-19T07:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552264#M156730</link>
      <description>&lt;P&gt;Do you mean use spath in my search query after payload?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please help me with the syntax?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 18:37:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552264#M156730</guid>
      <dc:creator>abidkar</dc:creator>
      <dc:date>2021-05-19T18:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552283#M156738</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your search&amp;gt;| spath | table *&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234552"&gt;@abidkar&lt;/a&gt;&amp;nbsp; In place of * , you can mentioned the field name which you want&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 20:30:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552283#M156738</guid>
      <dc:creator>dhirendra761</dc:creator>
      <dc:date>2021-05-19T20:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552303#M156745</link>
      <description>&lt;P&gt;Thanks for all your help but I am still getting the same output. I tried both ways:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"My Search"| table BAN, PAYLOAD | spath&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"My Search"| spath | table BAN, PAYLOAD&amp;nbsp; Still the output is same.&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 02:35:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552303#M156745</guid>
      <dc:creator>abidkar</dc:creator>
      <dc:date>2021-05-20T02:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552317#M156749</link>
      <description>&lt;P&gt;You are not giving us much to work with!&lt;/P&gt;&lt;P&gt;Is PAYLOAD a field which holds the json you are trying to extract from? if so, the syntax for spath will be something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=adms RestLoggingUtil XXXXXXXXXXX "/XXXXXXXXXXXXXX"
| spath input=PAYLOAD
| table BAN ClassifCode Date AcctID&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 20 May 2021 05:41:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552317#M156749</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-20T05:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552330#M156756</link>
      <description>&lt;P&gt;Also please make sure that key will be exist in json before extracting it.&lt;/P&gt;&lt;P&gt;I am not sure where is BAN and PAYLOAD in json&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 06:59:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552330#M156756</guid>
      <dc:creator>dhirendra761</dc:creator>
      <dc:date>2021-05-20T06:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552404#M156789</link>
      <description>&lt;P&gt;Here is my updated query;&lt;/P&gt;&lt;P&gt;index=adms RestLoggingUtil XXXXXXXXXXXXXX "/billing/v1/update-soc" |rex "billingAccountId \":\"(?&amp;lt;BAN&amp;gt;\d+)"| spath input=PAYLOAD | table socClassifVvCode, billingAccountId&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="abidkar_0-1621520288229.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14236iC304E63F1871419E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="abidkar_0-1621520288229.png" alt="abidkar_0-1621520288229.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and also getting following error&lt;/P&gt;&lt;DIV class="alert alert-error"&gt;5 errors occurred while the search was executing. Therefore, search results might be incomplete.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk-ss.t-mobile.com:8000/en-US/app/search/search?q=search%20index%3Dadms%20RestLoggingUtil%20NetflixFeatureChangeInitiated%20%22%2Fbilling%2Fv1%2Fupdate-soc%22%20%7Crex%20%22billingAccountId%20%20%5C%22%3A%5C%22(%3F%3CBAN%3E%5Cd%2B)%22%7C%20spath%20input%3DPAYLOAD%20%7C%20table%20socClassifVvCode%2C%20billingAccountId&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-15m&amp;amp;latest=now&amp;amp;display.page.search.tab=statistics&amp;amp;display.general.type=statistics&amp;amp;display.statistics.drilldown=row&amp;amp;sid=1621520083.1350100_56FFD111-A4B7-4C07-B06A-C5EA2094E84D#" target="_blank" rel="noopener"&gt;Hide errors.&lt;/A&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;Unknown error for indexer: prdtlplnk0113. Search Results might be incomplete! If this occurs frequently, check on the peer.&lt;/LI&gt;&lt;LI&gt;Unknown error for indexer: prdtlplnk0117. Search Results might be incomplete! If this occurs frequently, check on the peer.&lt;/LI&gt;&lt;LI&gt;Unknown error for indexer: prdtlplnk0132. Search Results might be incomplete! If this occurs frequently, check on the peer.&lt;/LI&gt;&lt;LI&gt;[prdplplnk0155] Error in 'DispatchCommandProcessor': Search results may be incomplete, peer prdplplnk0155's search ended prematurely. Error = Peer prdplplnk0155 will not return any results for this search, because the search head is using an outdated generation (search head gen_id=6093030; peer gen_id=6093032). This can be caused by the peer re-registering and the search head not yet updating to the latest generation. This should resolve itself shortly.&lt;/LI&gt;&lt;LI&gt;[prdplplnk016d] Error in 'DispatchCommandProcessor': Search results may be incomplete, peer prdplplnk016d's search ended prematurely. Error = Peer prdplplnk016d will not return any results for this search, because the search head is using an outdated generation (search head gen_id=6093030; peer gen_id=6093036). This can be caused by the peer re-registering and the search head not yet updating to the latest generation. This should resolve itself shortly&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Original search and output:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="abidkar_1-1621520486229.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14237iD33567A42834D000/image-size/medium?v=v2&amp;amp;px=400" role="button" title="abidkar_1-1621520486229.png" alt="abidkar_1-1621520486229.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;and Appreciate all your inputs and help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;Avanti&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 14:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552404#M156789</guid>
      <dc:creator>abidkar</dc:creator>
      <dc:date>2021-05-20T14:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552408#M156793</link>
      <description>&lt;P&gt;Try trimming PAYLOAD to make it a single object instead of a collection with a single object in.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval PAYLOAD="[ {\"socClassifVvCode\":\"XX\",\"logicalDate\":\"20210518\",\"billingAccountId\":\"XXXXXXXXX\",\"lastUpdateDate\":\"20210518181503\",\"msisdn\":null,\"subStatus\":null,\"lastUpdateStamp\":2245,\"deepEventName\":\"XXXXXXXXXX\",\"deepEventId\":\"2XXXXXXXX\",\"action\":\"XXX\",\"effectiveDate\":\"2021-05-18T17:00:00.000Z\",\"channelId\":\"XX\",\"productType\":null,\"requiredSoc\":null} ]"
| eval PAYLOAD=trim(PAYLOAD,"[] ")
| spath input=PAYLOAD&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 20 May 2021 14:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552408#M156793</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-20T14:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552435#M156797</link>
      <description>&lt;P&gt;Thanks a bunch to both of you for helping me on this one. It really makes it easy for me in this format. My next plan is to update my python code to directly insert this data in the table. If you have any other suggestions, please let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once again Thanks a bunch for all your help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;Avanti&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 17:26:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/552435#M156797</guid>
      <dc:creator>abidkar</dc:creator>
      <dc:date>2021-05-20T17:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554118#M157309</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need help with one more thing, is it possible to retrieve the data from SPLUNK search from a date? For e.g if I need the payload logs from April is it possible to download them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all your help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Avanti&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 15:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554118#M157309</guid>
      <dc:creator>abidkar</dc:creator>
      <dc:date>2021-06-02T15:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554119#M157310</link>
      <description>&lt;P&gt;I still don't know what a "payload log" is, but it should be possible to retrieve those from April.&amp;nbsp; Just use the time picker to select "Date Range", choose the beginning and end of April, then click Apply.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 15:54:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554119#M157310</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-06-02T15:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554156#M157318</link>
      <description>&lt;P&gt;Hi&amp;nbsp; Thanks for your response.&lt;/P&gt;&lt;P&gt;Here is my sample search query:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index=adms RestLoggingUtil XXXXXXXXXXXXXX "/billing/v1/update-soc" |rex "billingAccountId \":\"(?&amp;lt;BAN&amp;gt;\d+)"| spath input=PAYLOAD | table socClassifVvCode, billingAccountId&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The output of the search is payload data hence I mentioned payload in my earlier post.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;so the time picker should be part of my search query correct?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Just wanted to confirm before trying it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your help!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Avanti&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 22:27:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554156#M157318</guid>
      <dc:creator>abidkar</dc:creator>
      <dc:date>2021-06-02T22:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554210#M157328</link>
      <description>&lt;P&gt;No.&amp;nbsp;&lt;SPAN&gt;time picker is not part of your search query.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can select time range in button itself. refer attached image&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 787px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14449iC3B4C2976E3FACC6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 07:10:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554210#M157328</guid>
      <dc:creator>dhirendra761</dc:creator>
      <dc:date>2021-06-03T07:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554351#M157348</link>
      <description>&lt;P&gt;Thanks this did worked. however if I have to download the logs from my python code how can I use this date range option?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;currently I am doing this:&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;service&amp;nbsp;=&amp;nbsp;client.connect(&lt;/SPAN&gt;&lt;SPAN&gt;host&lt;/SPAN&gt;&lt;SPAN&gt;=HOST,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;port&lt;/SPAN&gt;&lt;SPAN&gt;=PORT,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;username&lt;/SPAN&gt;&lt;SPAN&gt;=USERNAME,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;password&lt;/SPAN&gt;&lt;SPAN&gt;=PASSWORD)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;kwargs_oneshot&amp;nbsp;=&amp;nbsp;{&lt;/SPAN&gt;&lt;SPAN&gt;"earliest_time"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"-60min"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;"latest_time"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"now"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;"search_mode"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"normal"&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"output_mode"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"csv"&lt;/SPAN&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;and planning to extend it to -24H but is it possible to provide a date range here?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Avanti&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 19:00:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554351#M157348</guid>
      <dc:creator>abidkar</dc:creator>
      <dc:date>2021-06-03T19:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK output from search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554354#M157349</link>
      <description>&lt;P&gt;Also I am facing another issue. The below code is just bringing 102 records however if download form the tool there 4000+ records&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;service&amp;nbsp;=&amp;nbsp;client.connect(&lt;/SPAN&gt;&lt;SPAN&gt;host&lt;/SPAN&gt;&lt;SPAN&gt;=HOST,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;port&lt;/SPAN&gt;&lt;SPAN&gt;=PORT,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;username&lt;/SPAN&gt;&lt;SPAN&gt;=USERNAME,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;password&lt;/SPAN&gt;&lt;SPAN&gt;=PASSWORD)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;kwargs_oneshot&amp;nbsp;=&amp;nbsp;{&lt;/SPAN&gt;&lt;SPAN&gt;"earliest_time"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"-24h"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;"latest_time"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"now"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;"search_mode"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"normal"&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"output_mode"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"csv"&lt;/SPAN&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;searchquery_oneshot&amp;nbsp;=&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;r&lt;/SPAN&gt;&lt;SPAN&gt;'search&amp;nbsp;index=adms&amp;nbsp;RestLoggingUtil FeatureChangeInitiated&amp;nbsp;"/billing/v1/update-soc"&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN&gt;rex&amp;nbsp;"billingAccountId&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;\"&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;\"&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;BAN&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;\d&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN&gt;)"&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;eval&amp;nbsp;PAYLOAD=trim(PAYLOAD,"[]&amp;nbsp;")&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;spath&amp;nbsp;input=PAYLOAD&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;table&amp;nbsp;socClassifVvCode,&amp;nbsp;logicalDate,&amp;nbsp;billingAccountId,&amp;nbsp;msisdn'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;oneshotsearch_results&amp;nbsp;=&amp;nbsp;service.jobs.oneshot(searchquery_oneshot,&amp;nbsp;**kwargs_oneshot)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;except&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Exception&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;as&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;e:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;print&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;"Reason:"&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;e)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;print&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;'Fething&amp;nbsp;results&amp;nbsp;from&amp;nbsp;splunk&amp;nbsp;server&amp;nbsp;-&amp;nbsp;please&amp;nbsp;wait&amp;nbsp;for&amp;nbsp;response&amp;nbsp;codes/error&amp;nbsp;messages...'&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;reader&amp;nbsp;=&amp;nbsp;results.ResultsReader(oneshotsearch_results)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;file&amp;nbsp;=&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"REDD_SOC_ScreenLimits_"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;+&amp;nbsp;currentDT.strftime(&lt;/SPAN&gt;&lt;SPAN&gt;"%Y%m%d%H%M%S"&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;+&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;".csv"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;f&amp;nbsp;=&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;open&lt;/SPAN&gt;&lt;SPAN&gt;(file,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;'wb'&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;f.write(oneshotsearch_results.read())&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;f.close()&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;print&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;"Data&amp;nbsp;Download&amp;nbsp;Completed"&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Not sure what am I missing&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 03 Jun 2021 19:22:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPLUNK-output-from-search-query/m-p/554354#M157349</guid>
      <dc:creator>abidkar</dc:creator>
      <dc:date>2021-06-03T19:22:12Z</dc:date>
    </item>
  </channel>
</rss>

