<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get big data with Splunk with Rest API without using Splunk Java SDK in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-big-data-with-Splunk-with-Rest-API-without-using/m-p/477695#M192735</link>
    <description>&lt;P&gt;This is with Curl, curl -u admin:changeme -k &lt;A href="https://localhost:8089/services/search/jobs"&gt;https://localhost:8089/services/search/jobs&lt;/A&gt; -d search="search *"&lt;BR /&gt;
how about with Restcall??&lt;BR /&gt;
i tried the below, but no luck...&lt;/P&gt;

&lt;P&gt;&lt;A href="https://localhost:8089/services/search/jobs/search=%22search"&gt;https://localhost:8089/services/search/jobs/search="search&lt;/A&gt; *"&lt;BR /&gt;
&lt;A href="https://localhost:8089/services/search/jobs?search=%22search"&gt;https://localhost:8089/services/search/jobs?search="search&lt;/A&gt; *"&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jan 2020 08:14:11 GMT</pubDate>
    <dc:creator>duddukuri</dc:creator>
    <dc:date>2020-01-13T08:14:11Z</dc:date>
    <item>
      <title>How to get big data with Splunk with Rest API without using Splunk Java SDK</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-big-data-with-Splunk-with-Rest-API-without-using/m-p/477693#M192733</link>
      <description>&lt;P&gt;By using the below implementation, able to query the Splunk with Rest API without using Splunk Java SDK&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;String uri = "https://&lt;/STRONG&gt;&lt;STRONG&gt;:8089/services/search/jobs/export?search=search ID=d19b7c20-22e2-4832-883e-8df3907fedc0";&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;import org.springframework.http.ResponseEntity;&lt;BR /&gt;
import org.springframework.http.client.support.BasicAuthenticationInterceptor;&lt;BR /&gt;
import org.springframework.web.client.RestTemplate;&lt;BR /&gt;
import org.springframework.web.util.UriComponentsBuilder;&lt;/P&gt;

&lt;P&gt;public class RestSplunkClient{&lt;BR /&gt;
public String get(String uri, String username, String password) {&lt;BR /&gt;
RestTemplate restTemplate = new RestTemplate();&lt;BR /&gt;
if(null!=username &amp;amp;&amp;amp; null!=password &amp;amp;&amp;amp; !username.isEmpty() &amp;amp;&amp;amp; !password.isEmpty()) {&lt;BR /&gt;
restTemplate.getInterceptors().add(new BasicAuthenticationInterceptor(username, password));&lt;BR /&gt;
}&lt;BR /&gt;
UriComponentsBuilder builder = UriComponentsBuilder.fromHttpUrl(uri);&lt;BR /&gt;
&lt;STRONG&gt;ResponseEntity response =restTemplate.getForEntity(builder.build().toUriString(), String.class); return response.getBody(); } }&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;The above Implementation works fine for events count upto 10000.&lt;BR /&gt;
I want to retrive the data with paging concept, when i tried with create of search job, it is not working.&lt;BR /&gt;
&lt;STRONG&gt;String uri = "https://&lt;/STRONG&gt;&lt;STRONG&gt;:8089/services/search/jobs?search=search ID=d19b7c20-22e2-4832-883e-8df3907fedc0";&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Kindly advice me in this regard.&lt;/P&gt;

&lt;P&gt;Thanks a lot in advance...&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 11:57:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-big-data-with-Splunk-with-Rest-API-without-using/m-p/477693#M192733</guid>
      <dc:creator>duddukuri</dc:creator>
      <dc:date>2020-01-10T11:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to get big data with Splunk with Rest API without using Splunk Java SDK</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-big-data-with-Splunk-with-Rest-API-without-using/m-p/477694#M192734</link>
      <description>&lt;P&gt;i want to create the search job and then want to retrive the data with pagging/offset concept&lt;BR /&gt;
String uri = "https://*&lt;STRONG&gt;&lt;EM&gt;:8089/services/search/jobs/&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;/results?output_mode=raw&amp;amp;&lt;/EM&gt;&lt;EM&gt;count=0&amp;amp;offset=0&lt;/EM&gt;*";&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 12:03:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-big-data-with-Splunk-with-Rest-API-without-using/m-p/477694#M192734</guid>
      <dc:creator>duddukuri</dc:creator>
      <dc:date>2020-01-10T12:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to get big data with Splunk with Rest API without using Splunk Java SDK</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-big-data-with-Splunk-with-Rest-API-without-using/m-p/477695#M192735</link>
      <description>&lt;P&gt;This is with Curl, curl -u admin:changeme -k &lt;A href="https://localhost:8089/services/search/jobs"&gt;https://localhost:8089/services/search/jobs&lt;/A&gt; -d search="search *"&lt;BR /&gt;
how about with Restcall??&lt;BR /&gt;
i tried the below, but no luck...&lt;/P&gt;

&lt;P&gt;&lt;A href="https://localhost:8089/services/search/jobs/search=%22search"&gt;https://localhost:8089/services/search/jobs/search="search&lt;/A&gt; *"&lt;BR /&gt;
&lt;A href="https://localhost:8089/services/search/jobs?search=%22search"&gt;https://localhost:8089/services/search/jobs?search="search&lt;/A&gt; *"&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 08:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-big-data-with-Splunk-with-Rest-API-without-using/m-p/477695#M192735</guid>
      <dc:creator>duddukuri</dc:creator>
      <dc:date>2020-01-13T08:14:11Z</dc:date>
    </item>
  </channel>
</rss>

