Getting Data In

Can i use rest API to see the latest result of a saved search?

kairobin
Path Finder

In the web Interface of Splunk - Saved Searches. One can view the latest result of a saved search.
This wil give the user the information without doing the search over again.

Does anybody have a way or an example on how to to get these result out using PHP, Curl og even Powershell?

Thanks in advance.
kai

Tags (2)
0 Karma
1 Solution

acharlieh
Influencer

With the REST API you could use /saved/searches/{name}/history to get all jobs, which will then return links to /search/jobs/{search_id} which is links or a minor url modification away from /search/jobs/{search_id}/results

There are examples all through the RESTREF doc that should help you out.

View solution in original post

kairobin
Path Finder

This wil give me much more to work With.
thank you

0 Karma

acharlieh
Influencer

With the REST API you could use /saved/searches/{name}/history to get all jobs, which will then return links to /search/jobs/{search_id} which is links or a minor url modification away from /search/jobs/{search_id}/results

There are examples all through the RESTREF doc that should help you out.

kairobin
Path Finder

Do you have an examle of this script?
I thought that this only worked with a live search. That for instanc $5 only has information when it ran a search.

0 Karma

harsmarvania57
Ultra Champion

This script will run when your schedule search will run.

0 Karma

harsmarvania57
Ultra Champion

Hi,

I am not sure about rest API, but you can create a script and you can use Splunk arguments to fectch the results, results will be in .tar.gz format, so you have to extract result with your script.

Ref. for splunk argument: http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Configuringscriptedalerts#Access_arguments_t...

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...