<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: API search query help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555421#M157663</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224479"&gt;@thaghost99&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As i initially mentioned, the message only appears in json mode regardless PIPE. output_mode=raw/csv never returns such message. See below.&lt;/P&gt;&lt;P&gt;WITH PIPE, message appears.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="venkatasri_0-1623384696627.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14591iAF0DE4E3F890A4DE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="venkatasri_0-1623384696627.png" alt="venkatasri_0-1623384696627.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;WITHOUT PIPE, message appears.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="venkatasri_0-1623385037778.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14593i9C554CDC6A5F0C18/image-size/medium?v=v2&amp;amp;px=400" role="button" title="venkatasri_0-1623385037778.png" alt="venkatasri_0-1623385037778.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;------&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
    <pubDate>Fri, 11 Jun 2021 04:17:27 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-06-11T04:17:27Z</dc:date>
    <item>
      <title>API search query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/554778#M157463</link>
      <description>&lt;P&gt;hi me again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;need help.&lt;/P&gt;&lt;P&gt;this search string works perfectly fine when doing search int he gui&lt;/P&gt;&lt;P&gt;this search works fine in SPLUNK APP = XADATA&lt;/P&gt;&lt;P&gt;index=xa_data sourcetype=xaupload Time_!=timestamp earliest=-40m latest=now |timechart span=40m eval(sum(Total_)) by time | eval Total_= sum(NULL) |where NULL &amp;gt; 0&lt;/P&gt;&lt;P&gt;but when i use the same search via API&lt;/P&gt;&lt;P&gt;i am getting this error.&lt;/P&gt;&lt;P&gt;any help will do thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thaghost99_0-1623099599458.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14520iCF99F089D685B99A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thaghost99_0-1623099599458.png" alt="thaghost99_0-1623099599458.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 21:00:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/554778#M157463</guid>
      <dc:creator>thaghost99</dc:creator>
      <dc:date>2021-06-07T21:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: API search query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/554806#M157475</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224479"&gt;@thaghost99&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The one you got is not an error 'messages' is an additional information that's being returned by API in outputode=json you can safely ignore it for your case. In this case Your search did not return any results, see the results[] is empty.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;To test this further you can set outputmode=raw and execute you won't get any output. Docs not covered how to get rid of these 'messages' in JSON mode.&lt;/P&gt;&lt;P&gt;If the search returns results you see the output as described here -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/RESTREF/RESTsearch#search.2Fjobs.2F.7Bsearch_id.7D.2Fresults" target="_blank"&gt;Search endpoint descriptions - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 02:16:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/554806#M157475</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-08T02:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: API search query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555396#M157656</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&lt;/P&gt;&lt;P&gt;hi thanks for the update. i think i found the problem. i think for some reason. it does not like the PIPE.&lt;/P&gt;&lt;P&gt;when i have the pipe it gives me that error. but when i remove it. it works just fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 00:26:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555396#M157656</guid>
      <dc:creator>thaghost99</dc:creator>
      <dc:date>2021-06-11T00:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: API search query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555399#M157657</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224479"&gt;@thaghost99&lt;/a&gt;&amp;nbsp; PIPE are usually fine, the same SPL that you use in UI can be used in API, expect explicit search command at the beginning of the query. which PIPE you are referring to?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 00:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555399#M157657</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-11T00:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: API search query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555405#M157659</link>
      <description>&lt;P&gt;this works....&lt;/P&gt;&lt;P&gt;curl -u admin:admin -k &lt;A href="https://xxxx:8089/services/search/jobs" target="_blank"&gt;https://xxxx:8089/services/search/jobs&lt;/A&gt; --data-urlencode search="search index=xa_data sourcetype=xaupload earliest=-20m latest=now NOT records"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this does not.&lt;/P&gt;&lt;P&gt;curl -u admin:admin -k &lt;A href="https://xxx:8089/services/searc" target="_blank"&gt;https://xxx:8089/services/searc&lt;/A&gt; h/jobs -d search="search index=xa_data sourcetype=xaupload earliest=-20m latest= now NOT records | table Total_"&lt;/P&gt;&lt;P&gt;NOTE: the Total_ is a valid field. and it works when doing it directly in the web splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thaghost99_0-1623376325917.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14587i77675841B1216303/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thaghost99_0-1623376325917.png" alt="thaghost99_0-1623376325917.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 01:52:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555405#M157659</guid>
      <dc:creator>thaghost99</dc:creator>
      <dc:date>2021-06-11T01:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: API search query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555407#M157660</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this works....&lt;/P&gt;&lt;P&gt;curl -u admin:admin -k&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://xxxx:8089/services/search/jobs" target="_blank" rel="nofollow noopener noreferrer"&gt;https://xxxx:8089/services/search/jobs&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;--data-urlencode search="search index=xa_data sourcetype=xaupload earliest=-20m latest=now NOT records"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this does not.&lt;/P&gt;&lt;P&gt;curl -u admin:admin -k&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://xxx:8089/services/searc" target="_blank" rel="nofollow noopener noreferrer"&gt;https://xxx:8089/services/searc&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;h/jobs -d search="search index=xa_data sourcetype=xaupload earliest=-20m latest= now NOT records | table Total_"&lt;/P&gt;&lt;P&gt;NOTE: the Total_ is a valid field. and it works when doing it directly in the web splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thaghost99_0-1623376418188.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14588iD06352C55B639C85/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thaghost99_0-1623376418188.png" alt="thaghost99_0-1623376418188.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 01:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555407#M157660</guid>
      <dc:creator>thaghost99</dc:creator>
      <dc:date>2021-06-11T01:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: API search query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555421#M157663</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224479"&gt;@thaghost99&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As i initially mentioned, the message only appears in json mode regardless PIPE. output_mode=raw/csv never returns such message. See below.&lt;/P&gt;&lt;P&gt;WITH PIPE, message appears.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="venkatasri_0-1623384696627.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14591iAF0DE4E3F890A4DE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="venkatasri_0-1623384696627.png" alt="venkatasri_0-1623384696627.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;WITHOUT PIPE, message appears.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="venkatasri_0-1623385037778.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14593i9C554CDC6A5F0C18/image-size/medium?v=v2&amp;amp;px=400" role="button" title="venkatasri_0-1623385037778.png" alt="venkatasri_0-1623385037778.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;------&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 04:17:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555421#M157663</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-11T04:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: API search query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555463#M157672</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i wish it works. but its empty results.&lt;/P&gt;&lt;P&gt;curl -u admin:admin -k &lt;A href="https://xxxx:8089/services/search/jobs/mysearch_1/results" target="_blank"&gt;https://xxxx:8089/services/search/jobs/mysearch_1/results&lt;/A&gt; --get -d output_mode=raw&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thaghost99_0-1623411440982.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14595i2682E0D5C6974432/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thaghost99_0-1623411440982.png" alt="thaghost99_0-1623411440982.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;should i log a ticket that it dont work?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 11:37:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/API-search-query-help/m-p/555463#M157672</guid>
      <dc:creator>thaghost99</dc:creator>
      <dc:date>2021-06-11T11:37:35Z</dc:date>
    </item>
  </channel>
</rss>

