Getting Data In

How read the data from splunk using search query using postman (not curl )get reuest.

kadamshridhar01
New Member

I want to know using postman how can find the result of below query
sourcetype="httpevent" 69272d19-53a9-4539-b149-9fc46bbc73cf

please find the attached image alt text

0 Karma

petom
Path Finder

There is a pretty good documentation available on Splunk website related to Splunk REST API.
You might want to have a look at it. The link below is related to Search endpoint:
https://docs.splunk.com/Documentation/Splunk/7.2.3/RESTREF/RESTsearch

But basically what you need is:
1) url is https://splunkserver:8089/services/jobs/export (export - to export search results, there are other search endpoints available too)
2) use basic authentication with your login name and password
3) method either POST or GET (see the docs), but let's say you use POST
4) as request parameters (key / value pairs in Params tab in Postman) use (note, colon below is a separator between key and value):

earliest_time :  -1h   (last 1 hour)
latest_time : now
output_mode : json  (or csv or xml, see the docs)
search : sourcetype="httpevent" 69272d19-53a9-4539-b149-9fc46bbc73cf

Results of the query will be in the format you specified in output_mode parameter.

0 Karma

niketn
Legend

@kadamshridhar01 sorry your question is not clear. Do you need help with sending data through HEC (via Postman) to Splunk? Or you are already sending data to Splunk and need help with writing SPL?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

kadamshridhar01
New Member

@niketnilay .Already data present in splunk .i want to retrieve it through postman with search criteria .I am new to splunk .what is SPL ?
If you give me below details retrieve data from splunk.
1)Request type (get/post) and url(https://localhost:8089/?)
2)request body if any require and format
3)headers list with value .

Currently i am able to hit request splunk using basic auth but I don't understand how to set search criteria to get data

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...