I am running a Job and retrieving datas over 1 Gb.
What happpens is that the job expires before I have time to load all the datas.
Is there a way to save the job using the API or increase the time before the job expires ?
You can use the job.touch() method to keep the job alive for the given ttl (time to live) or modify the ttl by using job.setttl(<ttl in seconds>).
job.setttl(<ttl in seconds>)
"Touching" the job every few thousand events might be a good idea. Additionally, using job.cancel()when you've finished processing the results can be used to remove the job.
You can see more info here: http://splunk-base.splunk.com/answers/50722/the-search-results-disappear-how-to-keep-them-longer-pyt...