Getting Data In

Python Rest API script

travismonta
New Member

After connecting to the splunk Rest API, I would like to run a search query built like this and stored in a variable.
hostname is equal to a string variable

searchQuery= "Search | sourcetype=Audit agent_name=hostname| head 5"

I would also like to add in the earliest time as a variable... not sure where to add this. I would then like to return the SID and data in a json format.

Thanks for helping!

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...