All Apps and Add-ons

find search body by sid

sakuraWu1
New Member

Hi all,

I have below link for a search, but when I click it, it shows nothing but only said: Unknown sid. I need to remove this search, but I don't know what is the search string inside.

May I know according to this sid, is there any way to find the search body from it?

https://***/search?sid=1476267099.133508

Thanks
wu

0 Karma

sbbadri
Motivator

So can get search body and other details by executing this rest command

| rest /services/search/jobs/1499263157.5501 splunk_server=local

Below is the link,

http://docs.splunk.com/Documentation/Splunk/6.6.2/RESTREF/RESTsearch

0 Karma

jplumsdaine22
Influencer

After the search expires it is no longer accessible by that URL. you can however check the _audit index. Try the following search

index=_audit search_id=1476267099.133508 info=granted search=* 

There is a field called search which will show you the SPL that was used

sakuraWu1
New Member

Sorry, I need recover this search ,not remove.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...