Getting Data In

REST API to automate CSV creation/export using Python script

jofermin
Explorer

I'm looking to write a Python script modeled after the example on this page: https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/RESTTUT/RESTsearches

However, the example python script only pulls the search ID. When I run the curl command to pull the search ID, then run the curl command to export the results of that search ID, I can't reliably export a CSV.

Here's the basic curl commands I'm using:

curl -u user:pass -k https://splunk.domain.com:8089/services/search/jobs -d search="search index=my_index | chart count by sourcetype"

Then I pull the searchID, for example 1234567.89

curl -u user:pass -k https://splunk.domain.com:8089/services/search/jobs/1234567.89/results --get -d output_mode=csv -o test.csv

After this step, if the search job isn't done, then the exported csv will be empty. I've tried to use the python command .sleep(60), but it only works if I'm searching earliest=@min-1min

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

You need to check the status of the job and when isDone = 1, then fetch the results. You can find the status here:

curl -u user:pass -k https://splunk.domain.com:8089/services/search/jobs/1234567.89/

So you'll need a loop in your code that checks status.

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

You need to check the status of the job and when isDone = 1, then fetch the results. You can find the status here:

curl -u user:pass -k https://splunk.domain.com:8089/services/search/jobs/1234567.89/

So you'll need a loop in your code that checks status.

0 Karma

jofermin
Explorer

Hey jkat, when I run that command, I receive an XML that has a bunch of <s:key name=.....> but there is no bool called isComplete.

0 Karma

jofermin
Explorer

Ah I found the bool it's <s:key name="isDone">1</s:key>thanks

0 Karma

jkat54
SplunkTrust
SplunkTrust

Thanks I updated my answer.

0 Karma
Get Updates on the Splunk Community!

Customer Experience | Splunk 2024: New Onboarding Resources

In 2023, we were routinely reminded that the digital world is ever-evolving and susceptible to new ...

Celebrate CX Day with Splunk: Take our interactive quiz, join our LinkedIn Live ...

Today and every day, Splunk celebrates the importance of customer experience throughout our product, ...

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...