Getting Data In

Is there a way to only get the response with "isDone" using the REST endpoint "search/jobs/{search_id}:"?

Kukkadapu
Path Finder

HI , When I try to get the status of the search_id using the REST endpoint "search/jobs/{search_id}: ", I see a lot of information in the response. Is there a way to only get the response to check the status of the job i.e. the field - "isDone" (without all the other information)

0 Karma
1 Solution

cmerriman
Super Champion

as far as i know, you just add something like |where isDone=1 to filter if the job is done or not. Otherwise you do a |fields isDone otherFields to only show fields you're interested in. I don't believe you can do this all in the rest command.

View solution in original post

cmerriman
Super Champion

as far as i know, you just add something like |where isDone=1 to filter if the job is done or not. Otherwise you do a |fields isDone otherFields to only show fields you're interested in. I don't believe you can do this all in the rest command.

Kukkadapu
Path Finder

Thanks for the reply cmerriman. We are calling the endpoint from the Java based app and is there any way to get only isDone instead of the whole payload?

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...