Dashboards & Visualizations

Can I retrieve job.sid with simple xml in Splunk Ent 6.1

CarlAus
Loves-to-Learn Lots

We are still running Enterprise 6.1, and I am unable to locate the relevant documentation.
I would like to know if I can access the job.sid using simple xml, and if so what the syntax might be.

I gather I am restricted to the <searchString> element as <search> & <query> are not relevant to version 6.1,

Any assistance would be most appreciated.

Labels (2)
Tags (2)
0 Karma

tscroggins
Champion

It's been a long time, but you may find what you need in $SPLUNK_HOME/share/splunk/search_mrsparkle/exposed/schema. The directory may be different, but there should be a simplexml.xsd schema file floating around to help you find elements, attributes, etc. The dashboard code is in search_mrsparkle as something like dashboard_*.js. You may need to de-minify the source, but you can search it and related files to see which built-in tokens are available.

0 Karma

CarlAus
Loves-to-Learn Lots

**at least I believe the <search> & <query> are not applicable to version 6.1!?

0 Karma

bowesmana
SplunkTrust
SplunkTrust

I am not sure when they came in, but looking at a Splunk 7 instance I have, there is a mix of searchString and <search><query> in the same dashboard.

Can you try converting the <searchString> to search/query and then addding an event handler outside the <query>, i.e.

<search>
  <query>
    your_search
  </query>
  <finalized>
    <set token="job_sid">$job.sid$</set>
  </finalized>
</search>

Not sure when/if finalized was changed to <done>, but I have seen <preview> and <progress> event handlers in old dashboards along with <finalized>.

See if any of this works.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...