Getting Data In

Not able to list out the saved search using REST API

anoopambli
Communicator

I am trying to figure out how to execute a saved search and get the results using the REST API. I have created few saved searches, but I'm not able to list them when I try curl -ks -u admin: https://splunkrest:8089/services/saved/searches. It just shows the default searches.

Any specific permission I need to set on the saved search so that they can be used via REST API?

0 Karma
1 Solution

somesoni2
Revered Legend
0 Karma

somesoni2
Revered Legend

Give this a try

curl -ks -u admin: https://splunkrest:8089/servicesNS/-/-/saved/searches
0 Karma

anoopambli
Communicator

I am able to view my saved search properties now. Thanks for your help. When I try to execute REST API call for dispatching the saved search, I get following error message, Any idea?

bash-3.2$ curl -ks -u : https://splunkrestsvc.fmrco.com/servicesNS/-/-/saved/searches/API_Test/dispatch -d force_dispatch=true

<msg type="ERROR">

In handler 'savedsearch': Cannot edit/create a saved search for wildcarded users or applications

0 Karma

anoopambli
Communicator

In handler 'savedsearch': Cannot edit/create a saved search for wildcarded users or applications is the error message.

0 Karma

somesoni2
Revered Legend

The endpoint is actually this

 https://splunkrestsvc.fmrco.com/servicesNS/USER/APP/saved/searches.

Once you've the property using first curl, grab the owner/author and the app context and use that for your second dispatch curl.

anoopambli
Communicator

Super cool, that worked. Thanks a ton.

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...