Getting Data In

REST API: searching piped into stats, no events available

twinspop
Influencer

If I run this search through the web interface:

error | stats count by host | sort - count

And then venture over to port 8089 and check the job, I can see the search summary and hit the Events link at the bottom of the page to get a list of the events.

However, if I run that search through the REST API, the Events link goes to an empty page. How can I get a list of the events from that search using the REST API?

Thanks, Jon

Tags (3)
0 Karma

twinspop
Influencer

If I set the status_buckets POST variable to 300 (as the is the default from the web interface search), I get eventAvailableCount > 0.

Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...